# URI query not matching all fields

**URL:** <https://discuss.elastic.co/t/uri-query-not-matching-all-fields/174523>\
**Category:** Elasticsearch\
**Created:** [March 29, 2019, 11:18am UTC](https://discuss.elastic.co/t/uri-query-not-matching-all-fields/174523 "2019-03-29T11:18:53Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![OrangeDog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orangedog/32/4630_2.png) [@OrangeDog](https://discuss.elastic.co/u/OrangeDog)\
**Post date:** [March 29, 2019, 11:18am UTC](https://discuss.elastic.co/t/uri-query-not-matching-all-fields/174523/1 "2019-03-29T11:18:53Z")

</div>

This query is returning documents that don't match all the listed fields (they don't even have these fields).

```
type.keyword:"rsyslog" AND severity.keyword:("alert" OR "err" OR "crit") AND @timestamp:[now-10m TO now]

```

Encoded:

```
/_search?q=type.keyword%3a%22rsyslog%22%20AND%20severity.keyword%3a(%22alert%22%20OR%20%22err%22%20OR%20%22crit%22)%20AND%20%40timestamp%3a%5bnow-10m%20TO%20now%5d

```

With `explain=true`:

```
"_explanation": {
  "value": 1,
  "description": "@timestamp:[1553857603072 TO 1553858203072]",
  "details": []
}
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 29, 2019, 2:12pm UTC](https://discuss.elastic.co/t/uri-query-not-matching-all-fields/174523/2 "2019-03-29T14:12:52Z")

</div>

Could you share a typical document which should match?

---

<div class="post-metadata">

**Author:** ![OrangeDog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orangedog/32/4630_2.png) [@OrangeDog](https://discuss.elastic.co/u/OrangeDog)\
**Post date:** [March 29, 2019, 3:31pm UTC](https://discuss.elastic.co/t/uri-query-not-matching-all-fields/174523/3 "2019-03-29T15:31:13Z")

</div>

The problem is that these documents _shouldn't_ match. The ones that should match are correctly returned by this query.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 29, 2019, 5:15pm UTC](https://discuss.elastic.co/t/uri-query-not-matching-all-fields/174523/4 "2019-03-29T17:15:30Z")

</div>

Could you provide a full recreation script as described in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will help to better understand what you are doing. Please, try to keep the example as simple as possible.

---

<div class="post-metadata">

**Author:** ![OrangeDog](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/orangedog/32/4630_2.png) [@OrangeDog](https://discuss.elastic.co/u/OrangeDog)\
**Post date:** [April 1, 2019, 4:10pm UTC](https://discuss.elastic.co/t/uri-query-not-matching-all-fields/174523/5 "2019-04-01T16:10:07Z")

</div>

Index templates are the defaults from the respective products.  
The search should return no hits, but returns the apm document.

```
POST /apm-test/_doc
{
  "@timestamp": 1553857900000
}
POST /logstash-test/_doc
{
  "@timestamp": 1553850000000,
  "type": "rsyslog",
  "severity": "err"
}
GET /_search?q=type.keyword%3a%22rsyslog%22%20AND%20severity.keyword%3a(%22alert%22%20OR%20%22err%22%20OR%20%22crit%22)%20AND%20%40timestamp%3a%5bnow-10m%20TO%20now%5d
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 2, 2019, 6:29pm UTC](https://discuss.elastic.co/t/uri-query-not-matching-all-fields/174523/6 "2019-04-02T18:29:09Z")

</div>

I ran:

```auto
DELETE apm-test,logstash-test
POST /apm-test/_doc
{
  "@timestamp": 1553857900000
}
POST /logstash-test/_doc
{
  "@timestamp": 1553850000000,
  "type": "rsyslog",
  "severity": "err"
}
GET /_search?q=type.keyword%3a%22rsyslog%22%20AND%20severity.keyword%3a(%22alert%22%20OR%20%22err%22%20OR%20%22crit%22)%20AND%20%40timestamp%3a%5bnow-10m%20TO%20now%5d

```

I'm getting:

```auto
{
  "took" : 74,
  "timed_out" : false,
  "_shards" : {
    "total" : 11,
    "successful" : 11,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : {
      "value" : 0,
      "relation" : "eq"
    },
    "max_score" : null,
    "hits" : []
  }
}

```

May be your reproduction script is not really accurate. Ie. there is no mapping so a default one is generated:

```auto
GET /apm-test/_mapping

```

gives:

```auto
{
  "apm-test" : {
    "mappings" : {
      "properties" : {
        "@timestamp" : {
          "type" : "long"
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2019, 6:29pm UTC](https://discuss.elastic.co/t/uri-query-not-matching-all-fields/174523/7 "2019-04-30T18:29:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
