# Discover Query Question

**URL:** <https://discuss.elastic.co/t/discover-query-question/42309>\
**Category:** Elasticsearch\
**Created:** [February 20, 2016, 3:54pm UTC](https://discuss.elastic.co/t/discover-query-question/42309 "2016-02-20T15:54:38Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![emilkacp](https://avatars.discourse-cdn.com/v4/letter/e/9e8a1a/32.png) [@emilkacp](https://discuss.elastic.co/u/emilkacp)\
**Post date:** [February 20, 2016, 3:54pm UTC](https://discuss.elastic.co/t/discover-query-question/42309/1 "2016-02-20T15:54:38Z")

</div>

Hello,

I am having trouble coming up with the correct query for a interesting situation:

Over a X hour period I may receive a output of process.status:failed or process.status:completed. Over this period let's say for process:1 I may of received a process.status that was initially failed but later re-attempted and it completed.

Is there a query I can run that will only show the process that contains process.status:failed but later did not contain a process.status:completed.

Basically just trying to weed out the process that ONLY failed during this complete timeframe?

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:14pm UTC](https://discuss.elastic.co/t/discover-query-question/42309/2 "2017-07-05T23:14:43Z")

</div>


