I'm working on AWS Elastic Search. I've come across one situation in my project where in my reports i have to search keywords like "corona virus".
But result should come with containing keywords like "Corona virus" and "corona" and "virus" and "coronavirus".
Please guide me how i should build my query DSL.
Note: Working on PHP language.
Appreciate your help.

You need to use shingle token filter
A token filter of type shingle that constructs shingles (token
n-grams) from a token stream. In other words, it creates combinations
of tokens as a single token. For example, the sentence "please divide
this sentence into shingles" might be tokenized into shingles "please
divide", "divide this", "this sentence", "sentence into", and "into
PUT index91
"settings": {
"analysis": {
"analyzer": {
"my_analyzer": {
"tokenizer": "standard",
"filter": [
"filter": {
"shingle_filter": {
"type": "shingle",
"min_shingle_size": 2,
"max_shingle_size": 3,
"output_unigrams": true,
"token_separator": ""
"mappings": {
"properties": {
"title": {
"type": "text",
"analyzer": "my_analyzer"
POST index91/_doc
"title":"corona virus"
GET index91/_search
"query": {
"match": {
"title": "coronavirus"
"hits" : [
"_index" : "index91",
"_type" : "_doc",
"_id" : "gNmUZHEBrJsHVOidaoU_",
"_score" : 0.9438393,
"_source" : {
"title" : "corona virus"
It will also work for "corona", "corona virus","virus"


Why doesn't the Keyword analyzer applied to a Text field return results when the pattern contains a dash in Regexp search query?

I have created a small example to demonstrate the specific issue I'm having. Briefly, when I create a multi-field mapping using a field type of Text and the Keyword analyzer, no documents are returned from an Elasticsearch Regexp search query that contains punctuation. I use a dash in the following example to demonstrate the problem.
I’m using Elasticsearch 7.10.2. The index I’m targeting is already populated with millions of documents. The field of type Text where I need to run some regular expressions uses the Standard (default) analyzer. I understand that, because the field gets tokenized by the Standard analyzer, the following request:
POST _analyze
"analyzer" : "default",
"text" : "The number is: 123-4576891-73.\n\n"
will yield three words: "the", "number", "is" and three groups of numbers: "123", "4567891", "73". It's obvious that a regular expression that relies on punctuation, like this one that contains two literal dashes:
will not return a result. Note, for those not familiar with this, regex shortcuts do not work for Lucene-based Elasticsearch requests (at least not yet). Here's a reference: Also, the use of word boundaries that I show in my examples (.*[^a-z0-9_])? and ([^a-z0-9_].*)? are from this post: Word boundary in Lucene regex.
To see this for yourself with an example, create and populate an index like so:
PUT /index-01
"settings": {
"number_of_shards": 1
"mappings": {
"properties": {
"text": { "type": "text" }
POST index-01/_doc/
"text": "The number is: 123-4576891-73.\n\n"
The following Regexp search query will return nothing because of the tokenization issue I described earlier:
POST index-01/_search
"size": 1,
"query": {
"regexp": {
"text": {
"value": "(.*[^a-z0-9_])?[0-9]{3}-[0-9]{7}-[0-9]{2}([^a-z0-9_].*)?",
"flags": "ALL",
"case_insensitive": true,
"max_determinized_states": 100000
"_source": false,
"highlight": {
"fields": {
"text": {}
Most posts suggest a quick fix would be to target the Keyword type multi-field instead of the text field. The Keyword multi-type field gets created automatically, as this shows:
GET index-01/_mapping/field/text
"index-01" : {
"mappings" : {
"text" : {
"full_name" : "text",
"mapping" : {
"text" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 256
Targeting the keyword field, I get return results for the following Regexp search query:
POST index-01/_search
"size": 1,
"query": {
"regexp": {
"text.keyword": {
"value": "(.*[^a-z0-9_])?[0-9]{3}-[0-9]{7}-[0-9]{2}([^a-z0-9_].*)?",
"flags": "ALL",
"case_insensitive": true,
"max_determinized_states": 100000
"_source": false,
"highlight": {
"fields": {
"text.keyword": {}
here's the hit-highlighted part of the result:
"highlight" : {
"text.keyword" : [
"<em>This is my number 123-4576891-73. Thanks\n\n</em>"
Because some of the documents have a large amount of text, I adjusted the text.keyword field size with ignore_above parameter:
PUT /index-01/_mapping
"properties": {
"text": {
"type": "text",
"fields": {
"keyword": {
"type": "keyword",
"ignore_above": 32766
However, this will skip some documents since the targeted index, contains larger text fields than this upper-bound for a field type Keyword. Also, according to the Elasticsearch documentation here:, this type of field is really designed for structured data, constant values and wildcard queries.
Following that guidance, I assigned the Keyword analyzer to a new field type Text (text.raw) by making this update to the mapping:
PUT /index-01/_mapping
"properties": {
"text": {
"type": "text",
"fields": {
"keyword": {
"type": "keyword",
"ignore_above": 32766
"raw": {
"type": "text",
"analyzer": "keyword",
"index": true
Now, you can see the additional mapping text.raw with this request:
GET index-01/_mapping/field/text
"index-01" : {
"mappings" : {
"text" : {
"full_name" : "text",
"mapping" : {
"text" : {
"type" : "text",
"fields" : {
"keyword" : {
"type" : "keyword",
"ignore_above" : 32766
"raw" : {
"type" : "text",
"analyzer" : "keyword"
Next, I verified that the data was, in fact, mapped to the multi-fields:
POST index-01/_search
"match_all": {}
"fields": ["text", "text.keyword", "text.raw"]
"hits" : [
"_index" : "index-01",
"_type" : "_doc",
"_id" : "2R-OgncBn-TNB4PjXYAh",
"_score" : 1.0,
"_source" : {
"text" : "The number is: 123-4576891-73.\n\n"
"fields" : {
"text" : [
"The number is: 123-4576891-73.\n\n"
"text.keyword" : [
"The number is: 123-4576891-73.\n\n"
"text.raw" : [
"The number is: 123-4576891-73.\n\n"
I also verified that the Keyword analyzer applied to the text.raw field contains a single token, as shown in the following request:
POST _analyze
"analyzer" : "keyword",
"text" : "The number is: 123-4576891-73.\n\n"
"tokens" : [
"token" : "The number is: 123-4576891-73.\n\n",
"start_offset" : 0,
"end_offset" : 32,
"type" : "word",
"position" : 0
However, the exact same Regexp search query targeting the text.raw field returns nothing:
POST index-01/_search
"size": 1,
"query": {
"bool": {
"must": [
"regexp": {
"text.raw": {
"value": "(.*[^a-z0-9_])?[0-9]{3}-[0-9]{7}-[0-9]{2}([^a-z0-9_].*)?",
"flags": "ALL",
"case_insensitive": true,
"max_determinized_states": 100000
"_source": false,
"highlight" : {
"fields" : {
"text.raw": {}
Please let me know if you know why I'm not getting back a result using the field type Text with the Keyword analyzer.

How to search both singular and plural form of word in elasticsearch?

I am making elastic query using Q object and I have indexed documents, one of the documents contains "jbl speakers are great", but my query has "speaker" instead of speakers how can I find this document with query string.
I have tried match_phrase but it is unable to find this document and when I had tried query_string it threw an error saying "query_string does not support for some key". I have also tried wildcard but that is also not working with query like
"query": {
"bool": {
"must": [
"match_phrase": {
"prod_group": "06"
"match_phrase": {
"prod_group": "apparel"
"wildcard": {
"prod_cat_for_search": "+speaker*"
"range": {
"date": {
"gte": "2018-04-07"
Q('match_phrase', prod_cat_for_search='speaker')
I expect the output document containing speakers but
actual output is no document containing speakers
The type of search you are looking for can be achieved by using stemmer token filter at the time of indexing.
Lets see how it work using the example mapping as below:
PUT test
"settings": {
"analysis": {
"analyzer": {
"my_analyzer": {
"type": "custom",
"filter": [
"tokenizer": "whitespace"
"filter": {
"my_stemmer": {
"type": "stemmer",
"name": "english"
"mappings": {
"doc": {
"properties": {
"description": {
"type": "text",
"analyzer": "my_analyzer",
"fields": {
"keyword": {
"type": "keyword"
For the field description in above mapping we have used analyzer as my_analyzer. This analyzer will apply token filters lowercase and my_stemmer. The my_stemmer will apply english stemming on the input value.
For e.g. if we index a document as below:
"description": "JBL speakers build with perfection"
The tokens that will get indexed are:
Notice speakers is indexed as speaker and perfection as perfect.
Now if you search for speakers or speaker both will match. Similarly, if you search for perfect the above document will match.
Why speakers or perfection will match might be a question arising in your mind. The reason for this is that by default elastic search apply the same analyzer that was used while indexing at the time of searching as well. So if you search for perfection it will be actually searching for perfect and hence the match.
More on stemming.

How do I get only the element values that match in the list in the Elastic Search?

[Hi, there]
I want to create an ES query that only retrieves certain elements that match in the list.
Here is my ES index schema.
"aliases": {},
"mappings": {
"test-1": {
"properties": {
"categoryName": {
"type": "keyword",
"index": false
"genDate": {
"type": "date"
"docList": {
"properties": {
"rank": {
"type": "integer",
"index": false
"doc-info": {
"properties": {
"docId": {
"type": "keyword"
"docName": {
"type": "keyword",
"index": false
"categoryId": {
"type": "keyword"
There are documents listed in the category. Documents in the list have their own information.
*search query in Kibana.
source": {
"categoryName" : "food" ,
"genDate" : 1577981646638,
"docList" [
"rank": 2,
"doc-info": {...}
"rank": 1,
"doc-info": {...}
"rank": 5,
"doc-info": {...}
"categoryId": "201"
First, I want to get only the element value that match in the list.
I would like to see only documents with rank 1 in the list. However, if I query using match as below, the result is the same as *search query in kibana.
*match query in Kibana.
GET test-es-2018/_search
"query": {
"bool": {
"must": [
{ "match": { "docList.rank": 1 } },
In my opinion, it seems to print the entire list because it contains a document with rank one.
What I want is:
source": {
"categoryName" : "food" ,
"genDate" : 1577981646638,
"docList" [
"rank": 1,
"doc-info": {...}
"categoryId": "201"
Is this possible?
Second, I want to sort the docList by rank. I tried sorting by creating a query like the following, but it was not sorted.
*sort query in Kibana.
GET test-es-2018/_search?
"query" : {
"bool" : {...}
"sort" : [
"docList.rank" : {
"order" : "asc"
What I want is:
source": {
"categoryName" : "food" ,
"genDate" : 1577981646638,
"docList" [
"rank": 1,
"doc-info": {...}
"rank": 2,
"doc-info": {...}
"rank": 5,
"doc-info": {...}
"categoryId": "201"
I do not know how to access the list. Is there a good idea for both of these issues?
In general you could use source filter to retrieve only part of the document but this way it's not possible to exclude some fields based on their values.
As far as I know Elasticsearch doesn't support changing order of field values in the _source. Partly the desired result can be achieved by using nested fields along with inner_hits -> sort query expression. This way sorted subhits will be returned in the inner_hits section of the response.
P.S. Typically working with Elasticsearch you should consider indexed document as the smallest indivisible search unit.

Regular Expressions and Elastic Search

I am trying to retrieve some company results using elasticsearch. I want to get companies that start with "A", then "B", etc. If I just do a pretty typical query with "prefix" like so
GET apple/company/_search
"query": {
"prefix": {
"name": "a"
"fields": [
"size": 100
But this will return Acme as well as Lemur and Associates, so I need to distinguish between A at the beginning of the whole name versus just A at the beginning of a word.
It would seem like regular expressions would come to the rescue here, but elastic search just ignores whatever I try. In tests with other applications, ^[\S]a* should get you anything that starts with A that doesn't have a space in front of it. Elastic search returns 0 results with the following:
GET apple/company/_search
"query": {
"regexp": {
"name": "^[\S]a*"
"fields": [
"size": 100
In FACT, the Sense UI for Elasticsearch will immediately alert you to a "Bad String Syntax Error". That's because even in a query elastic search wants some characters escaped. Nonetheless ^[\\S]a* doesn't work either.
Searching in Elasticsearch is both about the query itself, but also about the modelling of your data so it suits best the query to be used. One cannot simply index whatever and then try to struggle to come up with a query that does something.
The Elasticsearch way for your query is to have the following mapping for that field:
PUT /apple
"settings": {
"index": {
"analysis": {
"analyzer": {
"keyword_lowercase": {
"type": "custom",
"tokenizer": "keyword",
"filter": [
"mappings": {
"company": {
"properties": {
"name": {
"type": "string",
"fields": {
"analyzed_lowercase": {
"type": "string",
"analyzer": "keyword_lowercase"
And to use this query:
GET /apple/company/_search
"query": {
"prefix": {
"name.analyzed_lowercase": {
"value": "a"
GET /apple/company/_search
"query": {
"query_string": {
"query": "name.analyzed_lowercase:A*"

ElasticSearch RegExp Filter regex dash

I have a few documents in my ElasticSearch v1.2.1 like:
"tempSkipAfterSave": "false",
"variation": null,
"images": null,
"name": "Dolce & Gabbana Short Sleeve Coat",
"sku": "MD01575254-40-WHITE",
"user_id": "123foo",
"creation_date": null,
"changed": 1
where sku can be a variation such as : MD01575254-40-BlUE, MD01575254-38-WHITE
I can get my elastic search query to work with this:
"size": 1000,
"from": 0,
"filter": {
"and": [
"regexp": {
"sku": "md01575254.*"
"term": {
"user_id": "123foo"
"missing": {
"field": "project_id"
"query": {
"match_all": {}
I got all the variations back of sku: MD01575254*
However, the dash '-' is really screwing me up
when I change the regexp to:
"regexp": {
"sku": "md01575254-40.*"
I can't get any results back. I've also tried
"sku": "md01575254-40.*"
"sku": "md01575254\-40.*"
"sku": "md01575254-40-.*"
Just can't seem to make it work ? What am I don't wrong here?
This is because the default analyzer usually tokenizes at -, so your field is most likey saved like:
You can update your mapping to have a sku.raw field that would not be analyzed when indexed. This will require you to delete and re-index.
"<type>" : {
"properties" : {
"sku" : {
"type": "string",
"fields" : {
"raw" : {"type" : "string", "index" : "not_analyzed"}
Then you can query this new field which is not analyzed:
"query" : {
"regexp" : {
"sku.raw": "md01575254-40.*"
HTTP Endpoints:
The API to delete your current mapping and data is:
DELETE http://localhost:9200/<index>/<type>
The API to add your new mapping, with the raw SKU is:
PUT http://localhost:9200/<index>/<type>/_mapping
multiple fields in mapping
This can also we achieved by the following query. (use .keyword next to the field)
"regexp": {
"sku.keyword": "md01575254-40.*"