# Get times where document count = 0

**URL:** https://discuss.elastic.co/t/get-times-where-document-count-0/121628
**Category:** Elasticsearch
**Created:** [February 27, 2018, 10:26am UTC](https://discuss.elastic.co/t/get-times-where-document-count-0/121628 "2018-02-27T10:26:24Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)
#### Post date: [February 27, 2018, 10:26am UTC](https://discuss.elastic.co/t/get-times-where-document-count-0/121628/1 "2018-02-27T10:26:24Z")

</div>

Hi,

We have a problem, that a part of our application stalls from time to time.  
This results in **no** log lines. Normally we have multiple entries per second. When it stalls there are none.

Log lines are already indexed in elasticsearch.  
Now I need to query the times, where **no** loglines are present.

example:  
Our data looks like this:

 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/8/e/8ebafc672a3907c775e037a6653872be7a1a3360.png)

I would like to run a query like this:

- give me all time buckets (bucket size = 1s), where the count is 0.

Can I do this via kibana or elasticsearch?  
I could use the count api and query each second, but I think there should be a better approach.

Thanks, Andreas

---

<div class="post-metadata">

### Author: ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)
#### Post date: [February 27, 2018, 10:29am UTC](https://discuss.elastic.co/t/get-times-where-document-count-0/121628/2 "2018-02-27T10:29:24Z")

</div>

I need a post processing method. Initiating a 1s metric during logstash parsing should be avoided.

---

<div class="post-metadata">

### Author: ![asp](https://avatars.discourse-cdn.com/v4/letter/a/9fc348/32.png) [@asp](https://discuss.elastic.co/u/asp)
#### Post date: [February 27, 2018, 10:45am UTC](https://discuss.elastic.co/t/get-times-where-document-count-0/121628/3 "2018-02-27T10:45:45Z")

</div>

found out that adding

```
{"min_doc_count": 0}

```

does display the timestamps where the document count is 0. Unfortunately there is no flag like " **max** \_doc\_count"

So is there a way to filter the result in elasticsearch or kibana?

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 27, 2018, 10:45am UTC](https://discuss.elastic.co/t/get-times-where-document-count-0/121628/4 "2018-03-27T10:45:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
