# Elasticsearch query sort order index

**URL:** <https://discuss.elastic.co/t/elasticsearch-query-sort-order-index/137419>\
**Category:** Logstash\
**Created:** [June 26, 2018, 10:54am UTC](https://discuss.elastic.co/t/elasticsearch-query-sort-order-index/137419 "2018-06-26T10:54:16Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [June 26, 2018, 10:54am UTC](https://discuss.elastic.co/t/elasticsearch-query-sort-order-index/137419/1 "2018-06-26T10:54:17Z")

</div>

Hi,

if - in a Elasticsearch filter plugin - I do the following:

```
elasticsearch {
	hosts => ["elasticsearch:9200"]
	index => ["logstash-*"]
...

```

And let's assume I have several Logstash indexes like e.g.

```
logstash-2018.06.24
logstash-2018.06.25
logstash-2018.06.26

```

Where is the query supposed to search? Only in the latest? Only in the oldest? In all of them?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 26, 2018, 6:17pm UTC](https://discuss.elastic.co/t/elasticsearch-query-sort-order-index/137419/2 "2018-06-26T18:17:44Z")

</div>

It'll search all indexes that match the index name pattern you've given.

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [June 26, 2018, 7:18pm UTC](https://discuss.elastic.co/t/elasticsearch-query-sort-order-index/137419/3 "2018-06-26T19:18:20Z")

</div>

Thank you.

Providing in the elasticsearch filter plugin these settings:

```
result_size => 1
enable_sort => true

```

Do you think Logstash will return only the first match found in index logstash-2018.06.24 or something else?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 26, 2018, 7:33pm UTC](https://discuss.elastic.co/t/elasticsearch-query-sort-order-index/137419/4 "2018-06-26T19:33:34Z")

</div>

Assuming the timestamp is the sort key I'd expect it to return the first document in the first index.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2018, 7:33pm UTC](https://discuss.elastic.co/t/elasticsearch-query-sort-order-index/137419/5 "2018-07-24T19:33:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
