# Fetch Last 15 minute of data

**URL:** <https://discuss.elastic.co/t/fetch-last-15-minute-of-data/314695>\
**Category:** Elasticsearch\
**Created:** [September 19, 2022, 12:43pm UTC](https://discuss.elastic.co/t/fetch-last-15-minute-of-data/314695 "2022-09-19T12:43:16Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [September 19, 2022, 12:43pm UTC](https://discuss.elastic.co/t/fetch-last-15-minute-of-data/314695/1 "2022-09-19T12:43:16Z")

</div>

Here is my query for fetching the result of today last 15 minutes

```auto
{
  "query": {
     "bool": {
    "filter": [
      {
        "bool": {
          "should": [
            {
              "match_phrase": {
                "ResponseCode": "005"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "008"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "081"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "091"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "096"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "900"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "009"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "0068"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "153"
              }
            },
            {
              "range":
              {
                "timestamp":
                {
                   "gte":"now-15m"
                }
              }
            }
          ],
          "minimum_should_match": 1
        }
      }
    ],
    "must_not": []
  }
  }
}

```

But i am getting older data of previous month.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 19, 2022, 1:05pm UTC](https://discuss.elastic.co/t/fetch-last-15-minute-of-data/314695/2 "2022-09-19T13:05:26Z")

</div>

Can you share an example of a document from previous month that is being returned by this query?

---

<div class="post-metadata">

**Author:** ![BenB196](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/benb196/32/83401_2.png) [@BenB196](https://discuss.elastic.co/u/BenB196)\
**Post date:** [September 19, 2022, 1:05pm UTC](https://discuss.elastic.co/t/fetch-last-15-minute-of-data/314695/3 "2022-09-19T13:05:48Z")

</div>

You need to move your range filter to a new bool/should clause/filter. Currently you have it in the same filter as your `ResponseCode`, but then you also have `"minimum_should_match": 1` set, so your query is really saying, match one of these `ResponseCode`s **OR** any document with the `timestamp` range.

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [September 19, 2022, 5:32pm UTC](https://discuss.elastic.co/t/fetch-last-15-minute-of-data/314695/4 "2022-09-19T17:32:05Z")

</div>

@BenB196 , now i am getting zero result  
Can you please tell me where i am making mistake

```auto
{
  "query": {
     "bool": {
    "filter": [
      {
        "bool": {
          "should": [
            {
              "match_phrase": {
                "ResponseCode": "005"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "008"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "081"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "091"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "096"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "900"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "009"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "0068"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "153"
              }
            }
          ],
          "minimum_should_match": 1
        }
      },
      {
        "bool": {
          "should":
          {
             "range":
              {
                "timestamp":
                {
                   
                   "gte":"now-15m"
                }
              }
          }
        }
      }
    ],
    "must_not": []
  }
}
}

```

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [September 20, 2022, 6:56am UTC](https://discuss.elastic.co/t/fetch-last-15-minute-of-data/314695/5 "2022-09-20T06:56:58Z")

</div>

Thank you @leandrojmp and @BenB196 for your help i miss the @ in timestamp

```auto
{
  "query": {
     "bool": {
    "filter": [
      {
        "bool": {
          "should": [
            {
              "match_phrase": {
                "ResponseCode": "005"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "008"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "081"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "091"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "096"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "900"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "009"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "0068"
              }
            },
            {
              "match_phrase": {
                "ResponseCode": "153"
              }
            }
          ],
          "minimum_should_match": 1
        }
      },
      {
        "bool": {
          "should":{
          "range": {
            "@timestamp": {
              "gte": "now-15m"
            }
          }
          }
        }
      }
    ],
    "must_not": []
  }
}
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2022, 6:57am UTC](https://discuss.elastic.co/t/fetch-last-15-minute-of-data/314695/6 "2022-10-18T06:57:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
