# Get all items

**URL:** <https://discuss.elastic.co/t/get-all-items/282386>\
**Category:** Kibana\
**Created:** [August 24, 2021, 4:13pm UTC](https://discuss.elastic.co/t/get-all-items/282386 "2021-08-24T16:13:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nastya.JavaScript\_Ko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nastya.javascript_ko/32/89557_2.png) [@Nastya.JavaScript\_Ko](https://discuss.elastic.co/u/Nastya.JavaScript_Ko)\
**Post date:** [August 24, 2021, 4:13pm UTC](https://discuss.elastic.co/t/get-all-items/282386/1 "2021-08-24T16:13:22Z")

</div>

Hey! First time I work with elastic.  
I have a request like this - but it does not return data after August 10th.

```auto
{
  "query": {
           "bool": {
          "must_not": [
            {
              "term": {
                "suricata.eve.event_type": {
                  "value": "alert"
                }
              }
            },
              {
                "term": {
                  "suricata.eve.event_type": "anomaly"
                }
              }
          ] ,
            "filter": [
              {
                "exists": {
                  "field": "suricata.eve.ether.dest_mac"
                }
              },
              {
                "exists": {
                  "field": "suricata.eve.ether.src_mac"
                }
              },
              {
                "range": {
                  "@timestamp": {
                    "lte": "2021-08-24T10:49:26.593Z",
                    "format": "strict_date_optional_time"
                  }
                }
              },
              {
                "terms": {
                  "destination.ip": [
    "10.0.0.0/8",
    "100.64.0.0/10",
    "172.16.0.0/12",
    "192.168.0.0/16"
  ]
                }
              },
              {
                "terms": {
                  "source.ip": [
    "10.0.0.0/8",
    "100.64.0.0/10",
    "172.16.0.0/12",
    "192.168.0.0/16"
  ]
                }
              }
            ]
          }
        },
        "aggs": {
      "compositions": {
        "composite": {
          "size": 50000,
          "sources": [
            {
              "src_mac": {
                "terms": {
                  "field": "suricata.eve.ether.src_mac"
                }
              }
            },
            {
              "dest_mac": {
                "terms": {
                  "field": "suricata.eve.ether.dest_mac"
                }
              }
            },
            {
              "src_ip": {
                "terms": {
                  "field": "source.ip"
                }
              }
            },
            {
              "dest_ip": {
                "terms": {
                  "field": "destination.ip"
                }
              }
            }
          ]
        },
        "aggs": {
          "latest_hits": {
            "top_hits": {
              "sort": {
                "@timestamp": {
                  "order": "desc"
                }
              },
              "size": 1
            }
          }
        }
      }
    }
  }

```

I wanted to see all the data - but with such a request, the data is returned only for August 3.

```auto
{
  "query": {
           "bool": {}
        }
  }

```

How do I make a request to see all the data?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [August 24, 2021, 8:32pm UTC](https://discuss.elastic.co/t/get-all-items/282386/2 "2021-08-24T20:32:41Z")

</div>

Most likely is that queries by default only return 10 results the `size` parameter defaults to `10`

Try `"size: "1000",`

See Here

> **[Search API | Elasticsearch Guide \[7.14\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/search-search.html)**

If it is a very large set you will need to paginate

> **[Paginate search results | Elasticsearch Guide \[7.14\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/7.14/paginate-search-results.html)**

---

<div class="post-metadata">

**Author:** ![Nastya.JavaScript\_Ko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nastya.javascript_ko/32/89557_2.png) [@Nastya.JavaScript\_Ko](https://discuss.elastic.co/u/Nastya.JavaScript_Ko)\
**Post date:** [August 25, 2021, 1:11pm UTC](https://discuss.elastic.co/t/get-all-items/282386/3 "2021-08-25T13:11:39Z")

</div>

Thanks for the answer! I already figured it out myself and looked through what was needed in the morning 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 22, 2021, 1:11pm UTC](https://discuss.elastic.co/t/get-all-items/282386/4 "2021-09-22T13:11:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
