# ELK 5.5: Query with term and range filter

**URL:** <https://discuss.elastic.co/t/elk-5-5-query-with-term-and-range-filter/93876>\
**Category:** Elasticsearch\
**Created:** [July 20, 2017, 7:05am UTC](https://discuss.elastic.co/t/elk-5-5-query-with-term-and-range-filter/93876 "2017-07-20T07:05:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![prott8gf](https://avatars.discourse-cdn.com/v4/letter/p/ac8455/32.png) [@prott8gf](https://discuss.elastic.co/u/prott8gf)\
**Post date:** [July 20, 2017, 7:05am UTC](https://discuss.elastic.co/t/elk-5-5-query-with-term-and-range-filter/93876/1 "2017-07-20T07:05:01Z")

</div>

Hi,

I'm quite new to the beautiful world of elasticsearch and ran into a problem using the query language.

So I've installed a ELK 5.5 test environment including the WINLOGBEAT component, everthing is working fine.

Since the platform comes with a fancy query feature I wanted to query some of the events.

**Use case**  
I want to query events with a specfic ID which occured in the last 15 minutes and display all relevant event entries.

**This is my approach but it does not work**

```
{
  "query": {
"filtered": {
  "query": {
    "term": {"event_id": "4624"}
  },
  "filter": {
    "range": {
      "timestamp" : {"gt" : "now-5min"}
    }
  }
}
  }
}

```

**Result**

```
{
  "error": {
    "root_cause": [
      {
        "type": "parsing_exception",
        "reason": "no [query] registered for [filtered]",
        "line": 3,
        "col": 17
      }
    ],
    "type": "parsing_exception",
    "reason": "no [query] registered for [filtered]",
    "line": 3,
    "col": 17
  },
  "status": 400
}

```

Does anyone have a recommendation how to slove issues.

Thank you & kind regards

PR

---

<div class="post-metadata">

**Author:** ![Ivan](https://avatars.discourse-cdn.com/v4/letter/i/df788c/32.png) [@Ivan](https://discuss.elastic.co/u/Ivan)\
**Post date:** [July 20, 2017, 3:26pm UTC](https://discuss.elastic.co/t/elk-5-5-query-with-term-and-range-filter/93876/2 "2017-07-20T15:26:58Z")

</div>

You are using the old filtered query which has been removed in ES 5.x  
[https://www.elastic.co/guide/en/elasticsearch/reference/2.4/query-dsl-filtered-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/2.4/query-dsl-filtered-query.html)

The solution on that page of using the filter clause inside a bool query is  
the correct way to do things now.

---

<div class="post-metadata">

**Author:** ![prott8gf](https://avatars.discourse-cdn.com/v4/letter/p/ac8455/32.png) [@prott8gf](https://discuss.elastic.co/u/prott8gf)\
**Post date:** [July 24, 2017, 12:56pm UTC](https://discuss.elastic.co/t/elk-5-5-query-with-term-and-range-filter/93876/3 "2017-07-24T12:56:11Z")

</div>

Hi Ivan,

thank you for your support.

This solves my problem:

```
GET winlogbeat-*/_search
{
  "from": 0,
  "size": 1000,
  "query": {
"bool": {
  "must": {
    "term": {
      "event_id": "<ID-Number>"
    }
  },
  "filter": {
    "range": {
      "@timestamp": {
        "from": "now-5m",
        "to": "now"
      }
    }
  }
}
  },
  "sort": [
{
  "@timestamp": {
    "order": "desc"
  }
}
  ]
}

```

Kind Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2017, 12:56pm UTC](https://discuss.elastic.co/t/elk-5-5-query-with-term-and-range-filter/93876/4 "2017-08-21T12:56:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
