# Date query does not work

**URL:** <https://discuss.elastic.co/t/date-query-does-not-work/71828>\
**Category:** Kibana\
**Created:** [January 17, 2017, 8:32am UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828 "2017-01-17T08:32:07Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![Peter\_Andersson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_andersson/32/13173_2.png) [@Peter\_Andersson](https://discuss.elastic.co/u/Peter_Andersson)\
**Post date:** [January 17, 2017, 8:32am UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/1 "2017-01-17T08:32:07Z")

</div>

Hi i have the following query not `not @timestamp: [now/d+1h now/d+2h]` but it does not seem to work? what am i missing? (im trying to exclude a specific timespan from the query)

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [January 17, 2017, 12:29pm UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/2 "2017-01-17T12:29:29Z")

</div>

you could try with a query like this:

```auto
GET _search
{
  "query": {
    "bool": {
      "must_not": [{
         "range": {
            "FIELD": {
              "gte": 10,
              "lte": 20
            }
         }
      }]
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Peter\_Andersson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_andersson/32/13173_2.png) [@Peter\_Andersson](https://discuss.elastic.co/u/Peter_Andersson)\
**Post date:** [January 17, 2017, 12:38pm UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/3 "2017-01-17T12:38:11Z")

</div>

How would i express that in kibana? (im new and only know how to use the syntax you input in the textbox)

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [January 17, 2017, 1:38pm UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/4 "2017-01-17T13:38:25Z")

</div>

one way to do it would be:

- go to DISCOVER
- expand one record, next to your @timestamp field you will see a "zoom in" icon, which says filter on value (on hover).
- click that zoom in icon, filter will be added to your query bar.
- mouse over a filter and click EDIT icon
- you can now enter your custom filter, something like:

```auto
{
  "query": {
    "bool": {
      "must_not": [
        {
          "range": {
            "@timestamp": {
              "gte": "now/d+1h",
              "lte": "now/d+2h"
            }
          }
        }
      ]
    }
  }
}

```

- click DONE, your filter is updated to the custom one you entered.

let me know if this helps

---

<div class="post-metadata">

**Author:** ![Peter\_Andersson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_andersson/32/13173_2.png) [@Peter\_Andersson](https://discuss.elastic.co/u/Peter_Andersson)\
**Post date:** [January 17, 2017, 3:31pm UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/5 "2017-01-17T15:31:49Z")

</div>

Thanks i managed to enter the query but it did not work as expected it removes everything after `now/d+1h`. It should only remove records between `now/d+1h` and `now/d+2h`?

just for fun i changed `must_not` to `must`, correct me if im wrong but it should show 1h of data? but it shows all data after `now/d+1h`.

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [January 17, 2017, 6:18pm UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/6 "2017-01-17T18:18:37Z")

</div>

yes, it should show you 1h of data.

just to check ... you are trying to filter out all data from today 01:00AM till 02:00AM ?

---

<div class="post-metadata">

**Author:** ![Peter\_Andersson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_andersson/32/13173_2.png) [@Peter\_Andersson](https://discuss.elastic.co/u/Peter_Andersson)\
**Post date:** [January 18, 2017, 7:19am UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/7 "2017-01-18T07:19:59Z")

</div>

Yes im trying to filter out all data between 01:00 and 02:00 for today (its more specific in reality but if i can get this to work ill figure the rest out).  
Must result: ![](https://us1.discourse-cdn.com/elastic/original/2X/c/ca042a5d4db4995be705a7f2559d2e6186bb441f.png)  
Must not result: ![](https://us1.discourse-cdn.com/elastic/original/2X/9/9228f0df5248d87f54ea154f3faf8326c097a732.png)

Now im in UNC +1 so it might give a diff on one hour as the query seems to run at UNC+0.

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [January 18, 2017, 9:29am UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/8 "2017-01-18T09:29:48Z")

</div>

i was finally able to make it work with the following filter query:

```auto
{
  "query": {
    "bool": {
      "must": [
        {
          "range": {
            "@timestamp": {
              "lte": "now/d+2h",
              "gte": "now/d+25h"
            }
          }
        }
      ]
    }
  },
  "size": 0
}

```

this seems to be a bug, with lte now/d translates to today at 00:00, however with gte it seems that now/d translates to yesterday at 00:00 (thats why you need to add 25 hours instead of 1 to achieve desired results).

---

<div class="post-metadata">

**Author:** ![Peter\_Andersson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_andersson/32/13173_2.png) [@Peter\_Andersson](https://discuss.elastic.co/u/Peter_Andersson)\
**Post date:** [January 18, 2017, 9:59am UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/9 "2017-01-18T09:59:04Z")

</div>

> [@ppisljar](#):
>
> {  
> "query": {  
> "bool": {  
> "must": [  
> {  
> "range": {  
> "@timestamp": {  
> "lte": "now/d+2h",  
> "gte": "now/d+25h"  
> }  
> }  
> }  
> ]  
> }  
> },  
> "size": 0  
> }

hmm if i run this query i get no results at all...

---

<div class="post-metadata">

**Author:** ![ppisljar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ppisljar/32/11588_2.png) [@ppisljar](https://discuss.elastic.co/u/ppisljar)\
**Post date:** [January 18, 2017, 10:11am UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/10 "2017-01-18T10:11:38Z")

</div>

are you sure you have data from 01:00 to 02:00 am today ? it works ok for me ....

also it seems its not a bug but its intentional:

[https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html#ranges-on-dates](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html#ranges-on-dates)

try using lte+gt or lt+gte instead of lte+gte to get more consistent results.

---

<div class="post-metadata">

**Author:** ![Peter\_Andersson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/peter_andersson/32/13173_2.png) [@Peter\_Andersson](https://discuss.elastic.co/u/Peter_Andersson)\
**Post date:** [January 18, 2017, 10:20am UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/11 "2017-01-18T10:20:56Z")

</div>

I do have data but even if i didnt by using the +25h version all data gets removed, ie nothing is matched!!  
Filter disabled:

 ![](https://us1.discourse-cdn.com/elastic/original/2X/2/27628f30d528115d0f45374213c4be28466eba7c.png)  
Filter enabled:  
 ![](https://us1.discourse-cdn.com/elastic/original/2X/b/b601088ddf6bc1a7472b5566f465691f44e019cf.png)

Also tried to use `gt` or `lt` same result no matched data at all..  
What does `"size": 0` do?

---

<div class="post-metadata">

**Author:** ![Clinton\_Gormley](https://avatars.discourse-cdn.com/v4/letter/c/50afbb/32.png) [@Clinton\_Gormley](https://discuss.elastic.co/u/Clinton_Gormley)\
**Post date:** [January 18, 2017, 10:25am UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/12 "2017-01-18T10:25:27Z")

</div>

This is a bug in how the date round logic is applied for `lte`. I've opened [https://github.com/elastic/elasticsearch/issues/22670](https://github.com/elastic/elasticsearch/issues/22670)

You can work around it by using `lt` instead, which doesn't apply the rounding.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2017, 10:25am UTC](https://discuss.elastic.co/t/date-query-does-not-work/71828/13 "2017-02-15T10:25:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
