# How does timestamp range work with wildcard index?

**URL:** <https://discuss.elastic.co/t/how-does-timestamp-range-work-with-wildcard-index/356457>\
**Category:** Elasticsearch\
**Created:** [March 29, 2024, 10:52am UTC](https://discuss.elastic.co/t/how-does-timestamp-range-work-with-wildcard-index/356457 "2024-03-29T10:52:27Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Elena\_K](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elena_k/32/133113_2.png) [@Elena\_K](https://discuss.elastic.co/u/Elena_K)\
**Post date:** [March 29, 2024, 10:52am UTC](https://discuss.elastic.co/t/how-does-timestamp-range-work-with-wildcard-index/356457/1 "2024-03-29T10:52:27Z")

</div>

I'm trying to understand how search with a timestamp range works and whether I should use a specific index to make the search faster or if I can use a wildcard. The performance test didn't show any difference.

So I have a wildcard index `1p-minus-system-*` and it contains all the date indexes like

```auto
1p-minus-system-app-2024-03-27
1p-minus-system-web-2024-03-27
1p-minus-system-app-2024-03-26
1p-minus-system-web-2024-03-26
...

```

And I try to make a search for the last 10 minutes with the query

```auto
{
  "query": {
      "bool": {
          "must": [
              {"match_phrase": {"context.worker": psp}},
              {"range": {"@timestamp": {"gte": "now-10m/m", "lte": "now/m"}}},
          ],
      },
  },
  "_source": ["datetime.date", "context.operation_id", "context.worker", "short_message"],
  "sort": [
      {"@timestamp": {"order": "asc"}}
  ],
}

```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 29, 2024, 5:48pm UTC](https://discuss.elastic.co/t/how-does-timestamp-range-work-with-wildcard-index/356457/2 "2024-03-29T17:48:43Z")

</div>

Using a wildcard to match all indices is fine as querying an index that does not contain any documents matching the timestamp is very quick. This used to be expensive, which required various types of workarounds, but that is no longer the case.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2024, 5:49pm UTC](https://discuss.elastic.co/t/how-does-timestamp-range-work-with-wildcard-index/356457/3 "2024-04-26T17:49:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
