# Elasticsearch query without date range

**URL:** <https://discuss.elastic.co/t/elasticsearch-query-without-date-range/253165>\
**Category:** Elasticsearch\
**Created:** [October 23, 2020, 5:19pm UTC](https://discuss.elastic.co/t/elasticsearch-query-without-date-range/253165 "2020-10-23T17:19:21Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![gizem](https://avatars.discourse-cdn.com/v4/letter/g/7ea924/32.png) [@gizem](https://discuss.elastic.co/u/gizem)\
**Post date:** [October 23, 2020, 5:19pm UTC](https://discuss.elastic.co/t/elasticsearch-query-without-date-range/253165/1 "2020-10-23T17:19:22Z")

</div>

Hello,  
I wonder how does an elasticsearch query work without a date range?

Is there a default size of the result?

For example, what if I just only use lte for the range. Does query result include all the records from the first record to the lte value?

Regards,  
Gizem

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 24, 2020, 12:13am UTC](https://discuss.elastic.co/t/elasticsearch-query-without-date-range/253165/2 "2020-10-24T00:13:05Z")

</div>

> [@gizem](#):
>
> For example, what if I just only use lte for the range. Does query result include all the records from the first record to the lte value?

Yes.

---

<div class="post-metadata">

**Author:** ![gizem](https://avatars.discourse-cdn.com/v4/letter/g/7ea924/32.png) [@gizem](https://discuss.elastic.co/u/gizem)\
**Post date:** [October 24, 2020, 5:20am UTC](https://discuss.elastic.co/t/elasticsearch-query-without-date-range/253165/3 "2020-10-24T05:20:42Z")

</div>

Thank you @dadoonet.  
What if there is no date range? Is giving size better and make faster the query?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 24, 2020, 7:20am UTC](https://discuss.elastic.co/t/elasticsearch-query-without-date-range/253165/4 "2020-10-24T07:20:59Z")

</div>

If you don't have any query, it's faster. But if you have a query, reducing the number of indices by adding a time filter will also be faster to run the search.

What is exactly your question?

---

<div class="post-metadata">

**Author:** ![gizem](https://avatars.discourse-cdn.com/v4/letter/g/7ea924/32.png) [@gizem](https://discuss.elastic.co/u/gizem)\
**Post date:** [October 24, 2020, 8:27am UTC](https://discuss.elastic.co/t/elasticsearch-query-without-date-range/253165/5 "2020-10-24T08:27:58Z")

</div>

Okey, here is my question: if I define the parameter "size" in the query below, will it be faster? If not how can I make faster that query?

> ```
> query: {
> bool: {
> must: [
> {
> bool: {
> should: [
> {
> match_phrase: {
> logTag: LOG1
> }
> }
> {
> match_phrase: {
> logTag: LOG2
> }
> }
> ]
> minimum_should_match: 1
> }
> }
> ]
> filter: [
> {
> range: {
> @timestamp: {
> lte: 
> "2020-10-24T08:19:39.438Z"
> }
> }
> }
> ]
> should: [
> ]
> must_not: [
> ]
> }
> }
> aggs: {
> status: {
> top_hits: {
> docvalue_fields: [
> {
> field: Severity
> format: use_field_mapping
> }
> ]
> _source: [
> Severity
> ]
> size: 1
> sort: [
> {
> @timestamp: {
> order: desc
> }
> }
> ]
> }
> }
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 24, 2020, 1:04pm UTC](https://discuss.elastic.co/t/elasticsearch-query-without-date-range/253165/6 "2020-10-24T13:04:00Z")

</div>

If you have only one shard, I don't think it will change a lot. If you have time based indices you might be able to see a difference.

But the best thing to do is to test it 😏

---

<div class="post-metadata">

**Author:** ![gizem](https://avatars.discourse-cdn.com/v4/letter/g/7ea924/32.png) [@gizem](https://discuss.elastic.co/u/gizem)\
**Post date:** [October 24, 2020, 1:59pm UTC](https://discuss.elastic.co/t/elasticsearch-query-without-date-range/253165/7 "2020-10-24T13:59:28Z")

</div>

Okey, thanks...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 21, 2020, 1:59pm UTC](https://discuss.elastic.co/t/elasticsearch-query-without-date-range/253165/8 "2020-11-21T13:59:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
