Elasticsearch query time range issue

Could start again from the beginning? When there is no pit yet?

Something like:

POST /INDEXNAME/_pit?keep_alive=5m

And then share here the request AND the response.

Then run:

POST /_search 
{
   "size":1,
   "_source":[
      "kubernetes.container.name",
      "kubernetes.namespace",
      "message",
      "@timestamp"
   ],
   "query":{
      "bool":{
         "must":{
            "match":{
               "message":"exception"
            }
         },
         "filter":{
            "range":{
               "@timestamp":{
                  "gte":"2021-04-06T01:00:00",
                  "lte":"2021-04-06T18:00:00"
               }
            }
         }
      }
   },
   "pit":{
      "id":"PIT_ID_THAT_YOU_GOT",
      "keep_alive":"5m"
   },
   "sort":[
      {
         "@timestamp":"asc"
      }
   ]
}

And share here the request AND the result. Note that I set size: 1 so the result will be small enough to be pasted here.

Hi David,

PIT ID
{"id":"48myAwcaZGV2Mi1hcHBsb2dzLWJlLTIwMjEuMDQuMDgWY1d0MzhzSERRZnF6eGNNLVJubko0QQAWWWNmSml6aVdRR21yNFJpTWZ5U3FCdwAAAAAAAA0paBZveVVmVFRUM1JwVzFOcXpvSF9ITW5BABpkZXYyLWFwcGxvZ3MtYmUtMjAyMS4wNC4wNRZqWlAyYXdwSVRTS1hqRUh4bGI2Uk93ABZjUDZQYl9zcVJsQ0h1Sk5JS2RaRERnAAAAAAAAAmldFm9Ec1FORjQyUXZpam5VYTB4ekh2Y3cAGmRldjItYXBwbG9ncy1iZS0yMDIxLjA0LjA3FmFEQWotRURYU2pHbjVBdm1mTWtSNGcAFlljZkppemlXUUdtcjRSaU1meVNxQncAAAAAAAANKVwWb3lVZlRUVDNScFcxTnF6b0hfSE1uQQAaZGV2Mi1hcHBsb2dzLWJlLTIwMjEuMDQuMDIWTmNudXJCdS1UMldVQWtHcnhyR3NDZwAWY1A2UGJfc3FSbENIdUpOSUtkWkREZwAAAAAAAAJpXBZvRHNRTkY0MlF2aWpuVWEweHpIdmN3ABpkZXYyLWFwcGxvZ3MtYmUtMjAyMS4wNC4wNhZDUGRfUF9RMVJEdVMxYmpLNlViSWJBABZFamdFTTBoaFIyV0RzMF9DbkcycFFRAAAAAAAAAe06FnVVazE1dXRWVDJDTmdKWFUtekNRMmcAGmRldjItYXBwbG9ncy1iZS0yMDIxLjA0LjA0FkRNUUpHd1l3VHlLbjVJM0JOSlZRSGcAFkVqZ0VNMGhoUjJXRHMwX0NuRzJwUVEAAAAAAAAB7TkWdVVrMTV1dFZUMkNOZ0pYVS16Q1EyZwAaZGV2Mi1hcHBsb2dzLWJlLTIwMjEuMDQuMDMWZlhWT2FjR3hRRktFSDlhekNZNlBZQQAWRWpnRU0waGhSMldEczBfQ25HMnBRUQAAAAAAAAHtOBZ1VWsxNXV0VlQyQ05nSlhVLXpDUTJnAAcWRE1RSkd3WXdUeUtuNUkzQk5KVlFIZwAAFmNXdDM4c0hEUWZxenhjTS1Sbm5KNEEAABZmWFZPYWNHeFFGS0VIOWF6Q1k2UFlBAAAWQ1BkX1BfUTFSRHVTMWJqSzZVYkliQQAAFmFEQWotRURYU2pHbjVBdm1mTWtSNGcAABZqWlAyYXdwSVRTS1hqRUh4bGI2Uk93AAAWTmNudXJCdS1UMldVQWtHcnhyR3NDZwAA"}

Still same error

"root_cause" : [
{
"type" : "search_context_missing_exception",
"reason" : "No search context found for id [158044]"
},

POST /_search 
{
   "size":1,
   "_source":[
      "kubernetes.container.name",
      "kubernetes.namespace",
      "message",
      "@timestamp"
   ],
   "query":{
      "bool":{
         "must":{
            "match":{
               "message":"exception"
            }
         },
         "filter":{
            "range":{
               "@timestamp":{
                  "gte":"2021-04-06T01:00:00",
                  "lte":"2021-04-06T18:00:00"
               }
            }
         }
      }
   },
   "pit":{
      "id":"48myAwcaZGV2Mi1hcHBsb2dzLWJlLTIwMjEuMDQuMDgWY1d0MzhzSERRZnF6eGNNLVJubko0QQAWWWNmSml6aVdRR21yNFJpTWZ5U3FCdwAAAAAAAA0paBZveVVmVFRUM1JwVzFOcXpvSF9ITW5BABpkZXYyLWFwcGxvZ3MtYmUtMjAyMS4wNC4wNRZqWlAyYXdwSVRTS1hqRUh4bGI2Uk93ABZjUDZQYl9zcVJsQ0h1Sk5JS2RaRERnAAAAAAAAAmldFm9Ec1FORjQyUXZpam5VYTB4ekh2Y3cAGmRldjItYXBwbG9ncy1iZS0yMDIxLjA0LjA3FmFEQWotRURYU2pHbjVBdm1mTWtSNGcAFlljZkppemlXUUdtcjRSaU1meVNxQncAAAAAAAANKVwWb3lVZlRUVDNScFcxTnF6b0hfSE1uQQAaZGV2Mi1hcHBsb2dzLWJlLTIwMjEuMDQuMDIWTmNudXJCdS1UMldVQWtHcnhyR3NDZwAWY1A2UGJfc3FSbENIdUpOSUtkWkREZwAAAAAAAAJpXBZvRHNRTkY0MlF2aWpuVWEweHpIdmN3ABpkZXYyLWFwcGxvZ3MtYmUtMjAyMS4wNC4wNhZDUGRfUF9RMVJEdVMxYmpLNlViSWJBABZFamdFTTBoaFIyV0RzMF9DbkcycFFRAAAAAAAAAe06FnVVazE1dXRWVDJDTmdKWFUtekNRMmcAGmRldjItYXBwbG9ncy1iZS0yMDIxLjA0LjA0FkRNUUpHd1l3VHlLbjVJM0JOSlZRSGcAFkVqZ0VNMGhoUjJXRHMwX0NuRzJwUVEAAAAAAAAB7TkWdVVrMTV1dFZUMkNOZ0pYVS16Q1EyZwAaZGV2Mi1hcHBsb2dzLWJlLTIwMjEuMDQuMDMWZlhWT2FjR3hRRktFSDlhekNZNlBZQQAWRWpnRU0waGhSMldEczBfQ25HMnBRUQAAAAAAAAHtOBZ1VWsxNXV0VlQyQ05nSlhVLXpDUTJnAAcWRE1RSkd3WXdUeUtuNUkzQk5KVlFIZwAAFmNXdDM4c0hEUWZxenhjTS1Sbm5KNEEAABZmWFZPYWNHeFFGS0VIOWF6Q1k2UFlBAAAWQ1BkX1BfUTFSRHVTMWJqSzZVYkliQQAAFmFEQWotRURYU2pHbjVBdm1mTWtSNGcAABZqWlAyYXdwSVRTS1hqRUh4bGI2Uk93AAAWTmNudXJCdS1UMldVQWtHcnhyR3NDZwAA",
      "keep_alive":"5m"
   },
   "sort":[
      {
         "@timestamp":"asc"
      }
   ]
}

I executed same thing in devtools, working fine.

I need to do same thing in server.

{
"pit_id" : "48myAwcaZGV2Mi1hcHBsb2dzLWJlLTIwMjEuMDQuMDgWY1d0MzhzSERRZnF6eGNNLVJubko0QQAWWWNmSml6aVdRR21yNFJpTWZ5U3FCdwAAAAAAAA01GxZveVVmVFRUM1JwVzFOcXpvSF9ITW5BABpkZXYyLWFwcGxvZ3MtYmUtMjAyMS4wNC4wNRZqWlAyYXdwSVRTS1hqRUh4bGI2Uk93ABZZY2ZKaXppV1FHbXI0UmlNZnlTcUJ3AAAAAAAADTUZFm95VWZUVFQzUnBXMU5xem9IX0hNbkEAGmRldjItYXBwbG9ncy1iZS0yMDIxLjA0LjA3FmFEQWotRURYU2pHbjVBdm1mTWtSNGcAFmNQNlBiX3NxUmxDSHVKTklLZFpERGcAAAAAAAACcvcWb0RzUU5GNDJRdmlqblVhMHh6SHZjdwAaZGV2Mi1hcHBsb2dzLWJlLTIwMjEuMDQuMDIWTmNudXJCdS1UMldVQWtHcnhyR3NDZwAWWWNmSml6aVdRR21yNFJpTWZ5U3FCdwAAAAAAAA01GBZveVVmVFRUM1JwVzFOcXpvSF9ITW5BABpkZXYyLWFwcGxvZ3MtYmUtMjAyMS4wNC4wNhZDUGRfUF9RMVJEdVMxYmpLNlViSWJBABZjUDZQYl9zcVJsQ0h1Sk5JS2RaRERnAAAAAAAAAnL2Fm9Ec1FORjQyUXZpam5VYTB4ekh2Y3cAGmRldjItYXBwbG9ncy1iZS0yMDIxLjA0LjA0FkRNUUpHd1l3VHlLbjVJM0JOSlZRSGcAFkVqZ0VNMGhoUjJXRHMwX0NuRzJwUVEAAAAAAAAB8GkWdVVrMTV1dFZUMkNOZ0pYVS16Q1EyZwAaZGV2Mi1hcHBsb2dzLWJlLTIwMjEuMDQuMDMWZlhWT2FjR3hRRktFSDlhekNZNlBZQQAWRWpnRU0waGhSMldEczBfQ25HMnBRUQAAAAAAAAHwaBZ1VWsxNXV0VlQyQ05nSlhVLXpDUTJnAAcWRE1RSkd3WXdUeUtuNUkzQk5KVlFIZwAAFmNXdDM4c0hEUWZxenhjTS1Sbm5KNEEAABZmWFZPYWNHeFFGS0VIOWF6Q1k2UFlBAAAWQ1BkX1BfUTFSRHVTMWJqSzZVYkliQQAAFmFEQWotRURYU2pHbjVBdm1mTWtSNGcAABZqWlAyYXdwSVRTS1hqRUh4bGI2Uk93AAAWTmNudXJCdS1UMldVQWtHcnhyR3NDZwAA",
"took" : 54,
"timed_out" : false,
"_shards" : {
"total" : 7,
"successful" : 7,
"skipped" : 6,
"failed" : 0
},
"hits" : {
"total" : {
"value" : 88,
"relation" : "eq"
},
"max_score" : null,
"hits" : [
{
"_index" : "dev2-applogs-be-2021.04.06",
"_type" : "_doc",
"_id" : "GZrJpXgBm5biRIvY8df6",
"_score" : null,
"_source" : {
"kubernetes" : {
"container" : {
"name" : "hp-wcc-services-search"
},
"namespace" : "dev2"
},
"@timestamp" : "2021-04-06T06:06:11.335Z",
"message" : """2021-04-06 06:06:11.332 WARN [search-service,,,] Check result of the [AsyncReporter{org.springframework.cloud.sleuth.zipkin2.sender.RestTemplateSender@41be8db9}] contains an error [CheckResult{ok=false, error=org.springframework.web.client.ResourceAccessException: I/O error on POST request for "http://wcc-monitor.corp.hpicloud.net:9411/api/v2/spans": connect timed out; nested exception is java.net.SocketTimeoutException: connect timed out}]"""
},
"sort" : [
1617689171335,
48550
]
}
]
}
}

Please read again:

And:

Please format ALL the code parts as you did for only the last part of the code in this answer Elasticsearch query time range issue - #43 by suresh123.

Hi David,

It woks perfectly. Let me get more then 1 lakh count.

Thanks

Hi David,

I am getting sort for every request

"sort" : [
1617731997062,
223299
]

So, which sort numbers I need to add in search_after ?
"search_after": [
4098435132000,
4294967298
],

Both I guess.

There are thousands of sorts, which sort numbers i need to give exactly
Example

{
        "_index" : "dev-nginx-logs-2021.04.08",
        "_type" : "_doc",
        "_id" : "ROTPrngBm5biRIvY1qF3",
        "_score" : null,
        "_source" : {
          "request" : "image1",
          "referrer" : "-",
          "response_code" : 404,
          "@timestamp" : "2021-04-08T00:09:19.193Z"
        },
        "sort" : [
          1617840559193,
          4294968280
        ]
      },
      {
        "_index" : "dev-nginx-logs-2021.04.08",
        "_type" : "_doc",
        "_id" : "KuvPrngB9h4iHZ0t9DoD",
        "_score" : null,
        "_source" : {
          "request" : "/images/windows_image",
          "referrer" : "-",
          "response_code" : 404,
          "@timestamp" : "2021-04-08T00:09:26.194Z"
        },
        "sort" : [
          1617840566194,
          4294968281
        ]
      },

This is the search_after which sort I need to give.
"search_after": [
4098435132000,
4294967298
],

Hi David,

I took last value as it is giving Ascending order.

Thanks

I think everything is good. So we can close this long thread now.

Feel free to open a new question if needed.

Thanks you somuch.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.