# Filter timestamp range on es5

**URL:** <https://discuss.elastic.co/t/filter-timestamp-range-on-es5/89292>\
**Category:** Elasticsearch\
**Created:** [June 14, 2017, 4:44am UTC](https://discuss.elastic.co/t/filter-timestamp-range-on-es5/89292 "2017-06-14T04:44:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![procipher](https://avatars.discourse-cdn.com/v4/letter/p/aeb1de/32.png) [@procipher](https://discuss.elastic.co/u/procipher)\
**Post date:** [June 14, 2017, 4:44am UTC](https://discuss.elastic.co/t/filter-timestamp-range-on-es5/89292/1 "2017-06-14T04:44:09Z")

</div>

Hello @all, I have this mapping:

```
"@timestamp" : {
   "type" : "date",
   "format" : "strict_date_optional_time||epoch_millis"
}

```

And this structure:

`"@timestamp" :"2017-06-09T05:38:09+00:00"`

Now, I want to filter based on time range with:

```
"range" : {
            "@timestamp" : {
                "gte" : "now-1d/d",
                "lt" : "now/d"
            }
        },

```

But its not working.

When I go with:

```
"match" : {
            "@timestamp" :"2017-06-09T05:38:09+00:00",
            }

```

It gives positive result. Why the range query is not working? Is there any problem on es5?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 14, 2017, 7:38am UTC](https://discuss.elastic.co/t/filter-timestamp-range-on-es5/89292/2 "2017-06-14T07:38:45Z")

</div>

Hey

Have you tried `now-1d` and `now` for the ranges? As you havent mentioned what your query should query for, this is of course just a guess...

--Alex

---

<div class="post-metadata">

**Author:** ![procipher](https://avatars.discourse-cdn.com/v4/letter/p/aeb1de/32.png) [@procipher](https://discuss.elastic.co/u/procipher)\
**Post date:** [June 14, 2017, 8:43am UTC](https://discuss.elastic.co/t/filter-timestamp-range-on-es5/89292/3 "2017-06-14T08:43:45Z")

</div>

I separated match and range to separate query to this:

```
response = client.search(
    body={
    "size": 0,
    "query": {
        "match": {"host": "example.com"},
    },
    "query": {
        "range" : {
        "@timestamp" : {
           "gte" : "now-5d",
           "lt" : "now"
            }
        }        
    },          
    "aggs" : {
        "total_size" : { "sum" : { "field" : "size" } }
        }
    }
)

```

But I am getting different result for now-1d/d and now-1d. Its weird or I did sth wrong? Thanks.

PS: I got sth like this: "the /X operator will round back in time to the nearest start of that time period. So /d will round back to the start of the day". What does this mean in simple understandable way?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [June 16, 2017, 10:05am UTC](https://discuss.elastic.co/t/filter-timestamp-range-on-es5/89292/4 "2017-06-16T10:05:02Z")

</div>

Hey,

`now-5d` goes back from the current point in time (noon for me) to the noon 5 days ago.

`now/d` creates a date like `2017.12.31`, rounding to a full day.

--Alex

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2017, 10:05am UTC](https://discuss.elastic.co/t/filter-timestamp-range-on-es5/89292/5 "2017-07-14T10:05:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
