ElasticSearch query fields in disabled object

Viewed 461

I have an Elastic Search 6.8.7 cluster.

I have a column with this mapping:

"event_object": { "enabled": false, "type": "object" }

I want to search for records that match certain other criteria, and also have a particular value for a particular field field in this object.

So far, I have tried variations of doing a normal search for the indexed fields, and a filter script for the unindexed ones:

GET /my_index/_search
{
  "query":{
    "bool":{
      "must":{
        "query_string": {
          "query": "foo:bar"
        }
      }, 
      "filter": {
        "script": {
          "script": {
            "source": "doc[\"event_object\"][\"state\"].value == \"R\""
          }
        }
      }
    }
  },
  "terminate_after":1000, 
  "from":0,
  "size":1000
}

Which is a hodgepodge of testing myself forwards based on google searches. But I can't get things to even compile, let alone run and filter.

1 Answers

It is not possible to access the content of JSON objects that have enabled: false. From the official documentation:

Elasticsearch skips parsing of the contents of the field entirely. The JSON can still be retrieved from the _source field, but it is not searchable or stored in any other way

So even scripting will not help here.

However, there's one way to access this disabled data from scripting in a terms aggregation (using the include parameter and a top_hitssub-aggregation):

POST test/_search
{
  "query": {
    "match_all": {}
  },
  "aggs": {
    "state": {
      "terms": {
        "script": "params._source.event_object.state",
        "size": 100,
        "include": "R"
      },
      "aggs": {
        "hits": {
          "top_hits": {
            "size": 10
          }
        }
      }
    }
  }
}

And you'd get a response like this one:

  "aggregations" : {
    "state" : {
      "doc_count_error_upper_bound" : 0,
      "sum_other_doc_count" : 0,
      "buckets" : [
        {
          "key" : "R",
          "doc_count" : 1,
          "hits" : {
            "hits" : {
              "total" : {
                "value" : 1,
                "relation" : "eq"
              },
              "max_score" : 1.0,
              "hits" : [
                {
                  "_index" : "test",
                  "_type" : "_doc",
                  "_id" : "1",
                  "_score" : 1.0,
                  "_source" : {
                    "event_object" : {
                      "state" : "R"
                    },
                    "test" : "hello"
                  }
                }
              ]
            }
          }
        }
      ]
    }
  }
Related