# Efficient time-based multi index searches in ES6

**URL:** <https://discuss.elastic.co/t/efficient-time-based-multi-index-searches-in-es6/138423>\
**Category:** Elasticsearch\
**Created:** [July 3, 2018, 4:03pm UTC](https://discuss.elastic.co/t/efficient-time-based-multi-index-searches-in-es6/138423 "2018-07-03T16:03:43Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![BradVido](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bradvido/32/741_2.png) [@BradVido](https://discuss.elastic.co/u/BradVido)\
**Post date:** [July 3, 2018, 4:03pm UTC](https://discuss.elastic.co/t/efficient-time-based-multi-index-searches-in-es6/138423/1 "2018-07-03T16:03:43Z")

</div>

I recently upgraded from ES 1.7 to 6.3, so have a lot to learn. I thought i head read in some documentation that ES is smart enough to know what indices to query based on timestamp fields.

If i wanted to search 7/1 thru 7/3 is ES 1.7, I would search like this:

`logstash-2018-07-01,logstash-2018-07-02,logstash-2018-07-03/_search`

Is this still necessary, or can I simply do:  
`logstash-*/_search`  
and supply a range filter for the @timesamp field in the query and ES will figure out which indices to search?

---

<div class="post-metadata">

**Author:** ![BradVido](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bradvido/32/741_2.png) [@BradVido](https://discuss.elastic.co/u/BradVido)\
**Post date:** [July 6, 2018, 2:16pm UTC](https://discuss.elastic.co/t/efficient-time-based-multi-index-searches-in-es6/138423/2 "2018-07-06T14:16:10Z")

</div>

From my limited testing the queries seem to run just as fast if I specify logstash-\* or if i specifiy the exact index names. I just want to confirm this is the case.

---

<div class="post-metadata">

**Author:** ![BradVido](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bradvido/32/741_2.png) [@BradVido](https://discuss.elastic.co/u/BradVido)\
**Post date:** [July 24, 2018, 3:28pm UTC](https://discuss.elastic.co/t/efficient-time-based-multi-index-searches-in-es6/138423/3 "2018-07-24T15:28:29Z")

</div>

Any info on this? I can't find any conclusive documentation

---

<div class="post-metadata">

**Author:** ![ddorian43](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ddorian43/32/36093_2.png) [@ddorian43](https://discuss.elastic.co/u/ddorian43)\
**Post date:** [July 25, 2018, 5:26pm UTC](https://discuss.elastic.co/t/efficient-time-based-multi-index-searches-in-es6/138423/4 "2018-07-25T17:26:12Z")

</div>

`_index` filter is faster than `range` filter on more indexes.

Probably the `range` filter is smart enough to see `min/max` values of the `shards/segments` and early-terminate the query ?

Still, the shard would need to do some type of processing even with early-terminate, so better to restrict number of indexes that you're querying.

---

<div class="post-metadata">

**Author:** ![BradVido](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bradvido/32/741_2.png) [@BradVido](https://discuss.elastic.co/u/BradVido)\
**Post date:** [July 25, 2018, 8:03pm UTC](https://discuss.elastic.co/t/efficient-time-based-multi-index-searches-in-es6/138423/5 "2018-07-25T20:03:45Z")

</div>

I may be mixing "rollover" into this as well, interesting read: [https://www.elastic.co/blog/managing-time-based-indices-efficiently](https://www.elastic.co/blog/managing-time-based-indices-efficiently)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 22, 2018, 8:03pm UTC](https://discuss.elastic.co/t/efficient-time-based-multi-index-searches-in-es6/138423/6 "2018-08-22T20:03:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
