# Correct use of indicies

**URL:** <https://discuss.elastic.co/t/correct-use-of-indicies/31276>\
**Category:** Elasticsearch\
**Created:** [September 28, 2015, 5:18pm UTC](https://discuss.elastic.co/t/correct-use-of-indicies/31276 "2015-09-28T17:18:03Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Paul\_Cardy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_cardy/32/5090_2.png) [@Paul\_Cardy](https://discuss.elastic.co/u/Paul_Cardy)\
**Post date:** [September 28, 2015, 5:18pm UTC](https://discuss.elastic.co/t/correct-use-of-indicies/31276/1 "2015-09-28T17:18:03Z")

</div>

Hello all,

We're currently using logstash's one-day-per-index model of indices. This is working well within Kibana but I'm struggling to find information on how we should be limiting the number indices queried when writing our own queries. From what I understand, I can either list the filters, potentially with wildcards, in the query URI or add them to the Indices filter in the query itself. My first question is, are these two ways of specifying indices analogous? This post suggests that best practice is to put them on the URI:

> <https://stackoverflow.com/questions/26133395/filter-index-same-way-as-type-in-search-across-multiple-index-query-elasti>

This leads to my second question, if my indices are time based, how should I restrict the query to indices falling within the date range I'm interested in? If this is a whole month or year it's easy (just use a wildcard), but what if it's four weeks out of the month, do I have to list each of the 28 indicies within that range to the URI and/or filter? What does Kibana do?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 29, 2015, 12:29pm UTC](https://discuss.elastic.co/t/correct-use-of-indicies/31276/2 "2015-09-29T12:29:23Z")

</div>

KB 4.2 (will) handles that via [https://www.elastic.co/guide/en/elasticsearch/reference/2.0/search-field-stats.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.0/search-field-stats.html)

---

<div class="post-metadata">

**Author:** ![Paul\_Cardy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paul_cardy/32/5090_2.png) [@Paul\_Cardy](https://discuss.elastic.co/u/Paul_Cardy)\
**Post date:** [October 1, 2015, 2:22pm UTC](https://discuss.elastic.co/t/correct-use-of-indicies/31276/3 "2015-10-01T14:22:19Z")

</div>

Hi Warklom, thanks for the reply. I was aware of that new feature, but I'm struggling to understand how it will help. Could you explain?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 3, 2015, 11:26pm UTC](https://discuss.elastic.co/t/correct-use-of-indicies/31276/4 "2015-10-03T23:26:54Z")

</div>

It's a shortcut that lets someone look into any index and find (eg) the min and max documents within a timeframe.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:46pm UTC](https://discuss.elastic.co/t/correct-use-of-indicies/31276/5 "2017-07-05T23:46:55Z")

</div>


