# SQL

**URL:** https://forum.opensearch.org/c/plugins/sql/8.md

[Latest](https://forum.opensearch.org/latest.md) · [Categories](https://forum.opensearch.org/categories.md) · [Tags](https://forum.opensearch.org/tags.md)

---

## [About the SQL category](https://forum.opensearch.org/t/about-the-sql-category/18)

<div class="topic-metadata">

**Author:** [@carlmead](https://forum.opensearch.org/u/carlmead)\
**Replies:** 0\
**Last updated:** [March 1, 2019, 4:11am UTC](https://forum.opensearch.org/t/about-the-sql-category/18 "2019-03-01T04:11:20Z")

</div>

Extract insights out of OpenSearch using the familiar SQL query syntax, using aggregations, group by, and where clauses to investigate your data. SQL documentation: SQL - OpenSearch documentation

---

## [SQL plugin not returning correct count for attribute is NULL](https://forum.opensearch.org/t/sql-plugin-not-returning-correct-count-for-attribute-is-null/27535)

<div class="topic-metadata">

**Author:** [@bimlesh\_singh](https://forum.opensearch.org/u/bimlesh_singh)\
**Replies:** 5\
**Last updated:** [December 4, 2025, 1:12pm UTC](https://forum.opensearch.org/t/sql-plugin-not-returning-correct-count-for-attribute-is-null/27535 "2025-12-04T13:12:31Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser):2.19.4 and 2.18.0 Describe the issue: SQL plugin does not return correct data if below query is executed POST: \_plugins/\_sql { “query”:"SELECT COUNT(\*) AS C…

---

## [Unable to fetch result with SQL query](https://forum.opensearch.org/t/unable-to-fetch-result-with-sql-query/26799)

<div class="topic-metadata">

**Author:** [@SoumenduK](https://forum.opensearch.org/u/SoumenduK)\
**Replies:** 6\
**Last updated:** [September 24, 2025, 12:10am UTC](https://forum.opensearch.org/t/unable-to-fetch-result-with-sql-query/26799 "2025-09-24T00:10:57Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Describe the issue: We have Opensearch configured by the organisation in which I see that the index in the logs is always named with a timestamp, something l…

---

## [Query workbench (SQL and PPL) breaks due to something to do with network index pattern field aliases](https://forum.opensearch.org/t/query-workbench-sql-and-ppl-breaks-due-to-something-to-do-with-network-index-pattern-field-aliases/26344)

<div class="topic-metadata">

**Author:** [@tlacuache](https://forum.opensearch.org/u/tlacuache)\
**Replies:** 3\
**Last updated:** [September 4, 2025, 6:36pm UTC](https://forum.opensearch.org/t/query-workbench-sql-and-ppl-breaks-due-to-something-to-do-with-network-index-pattern-field-aliases/26344 "2025-09-04T18:36:07Z")

</div>

Versions: Opensearch 3.1.0, Dashboards 3.1.0 Describe the issue: For convenience in using Security Analytics, my project (Malcolm) calls the \_security\_analytics/mappings API with this mapping for our network logs: { …

---

## [How to Handle Complex JSON Data Types with OpenSearch SQL Plugin?](https://forum.opensearch.org/t/how-to-handle-complex-json-data-types-with-opensearch-sql-plugin/26560)

<div class="topic-metadata">

**Author:** [@lawotid](https://forum.opensearch.org/u/lawotid)\
**Replies:** 0\
**Last updated:** [August 30, 2025, 1:27pm UTC](https://forum.opensearch.org/t/how-to-handle-complex-json-data-types-with-opensearch-sql-plugin/26560 "2025-08-30T13:27:15Z")

</div>

Hello I have been testing the SQL plugin in OpenSearch to query JSON data stored inside indices. :slightly\_smiling\_face: While it works well for simple fields, I’m running into trouble when the JSON is deeply nested or …

---

## [Issue when trying to connect PowerBI](https://forum.opensearch.org/t/issue-when-trying-to-connect-powerbi/23964)

<div class="topic-metadata">

**Author:** [@almigvil](https://forum.opensearch.org/u/almigvil)\
**Replies:** 0\
**Last updated:** [March 28, 2025, 11:36am UTC](https://forum.opensearch.org/t/issue-when-trying-to-connect-powerbi/23964 "2025-03-28T11:36:04Z")

</div>

Hi, When trying to connect PowerBI to our OpenSearch, using host and port, without SSL, and with an admin internal user, we are getting following error: Which roughly translates to: We couldn’t connect you. Reason…

---

## [PPL query for nested fields](https://forum.opensearch.org/t/ppl-query-for-nested-fields/23725)

<div class="topic-metadata">

**Author:** [@sasi.424](https://forum.opensearch.org/u/sasi.424)\
**Replies:** 0\
**Last updated:** [March 10, 2025, 1:47pm UTC](https://forum.opensearch.org/t/ppl-query-for-nested-fields/23725 "2025-03-10T13:47:37Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): opensearch version 2.17 Describe the issue: PPL query on nested fields always returns zero records Configuration: PUT /patients { “mappings”: { “prope…

---

## [Error with SQL Subquery in OpenSearch: NullPointerException in FieldMappings](https://forum.opensearch.org/t/error-with-sql-subquery-in-opensearch-nullpointerexception-in-fieldmappings/22576)

<div class="topic-metadata">

**Author:** [@NewOne](https://forum.opensearch.org/u/NewOne)\
**Replies:** 0\
**Last updated:** [November 26, 2024, 11:12am UTC](https://forum.opensearch.org/t/error-with-sql-subquery-in-opensearch-nullpointerexception-in-fieldmappings/22576 "2024-11-26T11:12:19Z")

</div>

Hello, I’m encountering an issue that I can’t figure out the source of. According to the SQL subquery documentation, it’s possible to use queries like this: SELECT a1.firstname, a1.lastname, a1.balance FROM accounts a…

---

## [JDBC with squirrel or DBEaver](https://forum.opensearch.org/t/jdbc-with-squirrel-or-dbeaver/22355)

<div class="topic-metadata">

**Author:** [@cbarbier](https://forum.opensearch.org/u/cbarbier)\
**Replies:** 0\
**Last updated:** [November 8, 2024, 7:43am UTC](https://forum.opensearch.org/t/jdbc-with-squirrel-or-dbeaver/22355 "2024-11-08T07:43:01Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): Opensearch in AWS OpenSearch 2.15 Describe the issue: Connect using ODBC from Excel works fine. But when I try to connect using tier application with JDBC…

---

## [Count(\*) doesn't equevalent output of sql](https://forum.opensearch.org/t/count-doesnt-equevalent-output-of-sql/19736)

<div class="topic-metadata">

**Author:** [@m\_pahlevanzadeh](https://forum.opensearch.org/u/m_pahlevanzadeh)\
**Replies:** 1\
**Last updated:** [June 11, 2024, 9:34am UTC](https://forum.opensearch.org/t/count-doesnt-equevalent-output-of-sql/19736 "2024-06-11T09:34:47Z")

</div>

In Query Workbench I have: select count(\*) from fortigate-alias and output is 158816925 And in query workbench I have: Select \* from fortigate-alias Output is 200. why Query workbench limited me?

---

## [Invalid SQL query](https://forum.opensearch.org/t/invalid-sql-query/19742)

<div class="topic-metadata">

**Author:** [@m\_pahlevanzadeh](https://forum.opensearch.org/u/m_pahlevanzadeh)\
**Replies:** 1\
**Last updated:** [June 10, 2024, 5:36am UTC](https://forum.opensearch.org/t/invalid-sql-query/19742 "2024-06-10T05:36:27Z")

</div>

I have the following code with python: import requests response = requests.get("https://admin:mypasswd@localhost:9200/\_cat/plugins?v", verify=False) print(response.text) query = {"query": "select service from fortigat…

---

## [Python elasticsearch module](https://forum.opensearch.org/t/python-elasticsearch-module/19695)

<div class="topic-metadata">

**Author:** [@m\_pahlevanzadeh](https://forum.opensearch.org/u/m_pahlevanzadeh)\
**Replies:** 0\
**Last updated:** [June 5, 2024, 5:21am UTC](https://forum.opensearch.org/t/python-elasticsearch-module/19695 "2024-06-05T05:21:28Z")

</div>

when I test with curl, plugin sql is installed, then I install opensearchsql(cli) and it’s very useful for debugging. Now I need to write code via elasticsearch module of python(client side). My version is opensearch and…

---

## [OPENSearch JDBC drivers screw up connexion exceptions on other JDBC drivers :](https://forum.opensearch.org/t/opensearch-jdbc-drivers-screw-up-connexion-exceptions-on-other-jdbc-drivers/19655)

<div class="topic-metadata">

**Author:** [@patator23](https://forum.opensearch.org/u/patator23)\
**Replies:** 0\
**Last updated:** [May 31, 2024, 2:16pm UTC](https://forum.opensearch.org/t/opensearch-jdbc-drivers-screw-up-connexion-exceptions-on-other-jdbc-drivers/19655 "2024-05-31T14:16:54Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): opensearch-sql-jdbc-shadow-1.4.0.1.jar Linux centos Describe the issue: When I add opensearch JDBC drivers to my OS classpath, when i’m having connexion i…

---

## [How to import data from postgres to OpenSearch?](https://forum.opensearch.org/t/how-to-import-data-from-postgres-to-opensearch/7179)

<div class="topic-metadata">

**Author:** [@bashirahmad371](https://forum.opensearch.org/u/bashirahmad371)\
**Replies:** 4\
**Last updated:** [May 16, 2024, 6:04am UTC](https://forum.opensearch.org/t/how-to-import-data-from-postgres-to-opensearch/7179 "2024-05-16T06:04:29Z")

</div>

I want to connect OpenSearch with Postgres( or any other database) so that I can fetch my data in OpenSearch for indexing and other operations. Is there any documentation for that?

---

## [Error when trying to connect ODBC SSL](https://forum.opensearch.org/t/error-when-trying-to-connect-odbc-ssl/18924)

<div class="topic-metadata">

**Author:** [@apt](https://forum.opensearch.org/u/apt)\
**Replies:** 12\
**Last updated:** [April 26, 2024, 10:25am UTC](https://forum.opensearch.org/t/error-when-trying-to-connect-odbc-ssl/18924 "2024-04-26T10:25:50Z")

</div>

Hi, I am using opensearch 2.3.0 When I try to configure ODBC driver with SSL I get error like on the screenshot: What caught my attention is that in error message port number is reduced to 920. When I change opens…

---

## [COUNT aggregate function with subquery doesn't work](https://forum.opensearch.org/t/count-aggregate-function-with-subquery-doesnt-work/18835)

<div class="topic-metadata">

**Author:** [@oleg](https://forum.opensearch.org/u/oleg)\
**Replies:** 0\
**Last updated:** [April 11, 2024, 2:56pm UTC](https://forum.opensearch.org/t/count-aggregate-function-with-subquery-doesnt-work/18835 "2024-04-11T14:56:41Z")

</div>

Hello everyone, could someone enlighten me if it is possible to use any aggregation functions within SQL syntax with subquery. Without COUNT function everything works as expected. (Also there is some non-standart behavio…

---

## [How to get all rows of an sql query?](https://forum.opensearch.org/t/how-to-get-all-rows-of-an-sql-query/18332)

<div class="topic-metadata">

**Author:** [@abhineet1313](https://forum.opensearch.org/u/abhineet1313)\
**Replies:** 1\
**Last updated:** [March 18, 2024, 11:11pm UTC](https://forum.opensearch.org/t/how-to-get-all-rows-of-an-sql-query/18332 "2024-03-18T23:11:49Z")

</div>

Hi Need some help to understand how to read all rows from a query like below: POST \_plugins/\_sql { “query”: “”" select distinct text\_field,field2 from index where text\_field like ‘%xyz%’ “”" } Index has about 200…

---

## [Count with joins is giving null results](https://forum.opensearch.org/t/count-with-joins-is-giving-null-results/17825)

<div class="topic-metadata">

**Author:** [@AkshayC977](https://forum.opensearch.org/u/AkshayC977)\
**Replies:** 0\
**Last updated:** [February 9, 2024, 7:38am UTC](https://forum.opensearch.org/t/count-with-joins-is-giving-null-results/17825 "2024-02-09T07:38:12Z")

</div>

Count with joins is giving null results select count(p.id) from projects p join calls cl on p.id = cl.projectId where p.type=‘subproject’

---

## [Subdate/date\_sub query method not supported](https://forum.opensearch.org/t/subdate-date-sub-query-method-not-supported/9252)

<div class="topic-metadata">

**Author:** [@DrEdWilliams](https://forum.opensearch.org/u/DrEdWilliams)\
**Replies:** 9\
**Last updated:** [February 2, 2024, 4:08pm UTC](https://forum.opensearch.org/t/subdate-date-sub-query-method-not-supported/9252 "2024-02-02T16:08:14Z")

</div>

I must be doing something wrong, but I’m not sure what … I’m trying to do a SQL query like this (names change to protect the guilty): POST /\_plugins/\_sql { "query": "SELECT nodename,state FROM nodes WHERE @timestamp \>…

---

## [Is opensearch a suitable datasource for querying it from Tableau?](https://forum.opensearch.org/t/is-opensearch-a-suitable-datasource-for-querying-it-from-tableau/17587)

<div class="topic-metadata">

**Author:** [@mabumann](https://forum.opensearch.org/u/mabumann)\
**Replies:** 0\
**Last updated:** [January 26, 2024, 8:44am UTC](https://forum.opensearch.org/t/is-opensearch-a-suitable-datasource-for-querying-it-from-tableau/17587 "2024-01-26T08:44:47Z")

</div>

Hi. We are generally using MSSQL as backend for our Tableau server. Now we intend to implement some more complex dashboards in Tableau which would aggregate millions of records. MSSQL is way to slow for the task and we …

---

## [How can i do mSearch with SQL/PPL Query? Is this possible currently](https://forum.opensearch.org/t/how-can-i-do-msearch-with-sql-ppl-query-is-this-possible-currently/17249)

<div class="topic-metadata">

**Author:** [@ramda](https://forum.opensearch.org/u/ramda)\
**Replies:** 0\
**Last updated:** [December 27, 2023, 5:19am UTC](https://forum.opensearch.org/t/how-can-i-do-msearch-with-sql-ppl-query-is-this-possible-currently/17249 "2023-12-27T05:19:19Z")

</div>

How can i do mSearch with SQL/PPL Query? Is this possible currently With DSL Query, i can use mSearch to have multiple search on various task in a single request for different indexes. Can i do the same with PPL or SQL…

---

## [Executing SQL via PPL](https://forum.opensearch.org/t/executing-sql-via-ppl/16393)

<div class="topic-metadata">

**Author:** [@mkhl](https://forum.opensearch.org/u/mkhl)\
**Replies:** 5\
**Last updated:** [October 26, 2023, 7:27pm UTC](https://forum.opensearch.org/t/executing-sql-via-ppl/16393 "2023-10-26T19:27:45Z")

</div>

Hello, Is it possible to execute SQL via PPL? I’m asking because it seems it may overcome some JOINs limitations. WDYT? Sadly, seems like JOIN in SQL disables “filter” feature.

---

## [Complex queries - LEFT JOIN ON WHERE NULL issue](https://forum.opensearch.org/t/complex-queries-left-join-on-where-null-issue/5165)

<div class="topic-metadata">

**Author:** [@Jonas](https://forum.opensearch.org/u/Jonas)\
**Replies:** 2\
**Last updated:** [October 22, 2023, 1:19pm UTC](https://forum.opensearch.org/t/complex-queries-left-join-on-where-null-issue/5165 "2023-10-22T13:19:32Z")

</div>

Hello, i ask for your help with complex queries, data: Two indices in elasticsearch Goal: I want to select all gateway\_names within one index that are not existent in the other. Approach: SELECT \* FROM index\_large …

---

## [Update underlying libs](https://forum.opensearch.org/t/update-underlying-libs/16118)

<div class="topic-metadata">

**Author:** [@annvzel](https://forum.opensearch.org/u/annvzel)\
**Replies:** 0\
**Last updated:** [October 3, 2023, 10:02am UTC](https://forum.opensearch.org/t/update-underlying-libs/16118 "2023-10-03T10:02:02Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 2.0.8,2.10.0 Describe the issue: Hi, the Druid lib version included (1.0.15) is pretty old. Versions of alibaba-druid 1.0.0 - 1.1.19 are reported as vuln…

---

## [OpenSearch DataSources](https://forum.opensearch.org/t/opensearch-datasources/16026)

<div class="topic-metadata">

**Author:** [@hm21](https://forum.opensearch.org/u/hm21)\
**Replies:** 0\
**Last updated:** [September 24, 2023, 12:00pm UTC](https://forum.opensearch.org/t/opensearch-datasources/16026 "2023-09-24T12:00:58Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 2.9.0 Ubuntu 22.04 Describe the issue: I don’t really get what difference between the data sources feature added via \_datasources API endpoint when it com…

---

## [AWS Opensearch Connectivity with On Prem Informatica](https://forum.opensearch.org/t/aws-opensearch-connectivity-with-on-prem-informatica/15591)

<div class="topic-metadata">

**Author:** [@SriMaz](https://forum.opensearch.org/u/SriMaz)\
**Replies:** 1\
**Last updated:** [August 21, 2023, 3:30pm UTC](https://forum.opensearch.org/t/aws-opensearch-connectivity-with-on-prem-informatica/15591 "2023-08-21T15:30:19Z")

</div>

AWS Opensearch 2.7 Latest JDBC driver Describe the issue: We are using Informatica DIE on premise to connect to AWS Opensearch cluster within VPC. Connection is successful , however we are not able to see the indexes …

---

## [SQL JOIN with Subquery issue](https://forum.opensearch.org/t/sql-join-with-subquery-issue/4873)

<div class="topic-metadata">

**Author:** [@mhkang589](https://forum.opensearch.org/u/mhkang589)\
**Replies:** 5\
**Last updated:** [June 13, 2023, 5:30am UTC](https://forum.opensearch.org/t/sql-join-with-subquery-issue/4873 "2023-06-13T05:30:35Z")

</div>

This is my query. select a.name from ( select distinct ext.keyword as name from log-210110) a join ( select distinct ext.keyword as name from log-210111) b on a.name = b.name My query returns error below. { …

---

## [Retrieve the original raw document via SQL](https://forum.opensearch.org/t/retrieve-the-original-raw-document-via-sql/14164)

<div class="topic-metadata">

**Author:** [@PeterS](https://forum.opensearch.org/u/PeterS)\
**Replies:** 3\
**Last updated:** [May 5, 2023, 9:24am UTC](https://forum.opensearch.org/t/retrieve-the-original-raw-document-via-sql/14164 "2023-05-05T09:24:00Z")

</div>

Is it possible to get the original raw document via SQL? E.g.: SELECT \_source FROM index WHERE indexedField = ... Currently, I have to map arrays as “nested” type and use self-joins to access objects in arrays. With ra…

---

## [How search in firsts characters](https://forum.opensearch.org/t/how-search-in-firsts-characters/7423)

<div class="topic-metadata">

**Author:** [@diego](https://forum.opensearch.org/u/diego)\
**Replies:** 3\
**Last updated:** [April 24, 2023, 4:47pm UTC](https://forum.opensearch.org/t/how-search-in-firsts-characters/7423 "2023-04-24T16:47:36Z")

</div>

Hi, I’m a beginner in opensearch and I was having difficulties in elasticsearch and in this I found a possibility to use it in opensearch. I wanted to know if I would have a possibility to perform the search in a specif…

---

## [Index patterns for Querying nested collection](https://forum.opensearch.org/t/index-patterns-for-querying-nested-collection/13917)

<div class="topic-metadata">

**Author:** [@PeterS](https://forum.opensearch.org/u/PeterS)\
**Replies:** 8\
**Last updated:** [April 17, 2023, 9:14am UTC](https://forum.opensearch.org/t/index-patterns-for-querying-nested-collection/13917 "2023-04-17T09:14:58Z")

</div>

Versions (relevant - OpenSearch/Dashboard/Server OS/Browser): 2.6.0 Describe the issue: I’m querying nested collections as described in the documentation: I figured out that the query only works, when the array is …

[Next page](https://forum.opensearch.org/c/plugins/sql/8.md?page=1)
