# How to query for changes

**URL:** https://discuss.elastic.co/t/how-to-query-for-changes/215812
**Category:** Elasticsearch
**Created:** [January 21, 2020, 2:20am UTC](https://discuss.elastic.co/t/how-to-query-for-changes/215812 "2020-01-21T02:20:56Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![uniquename](https://avatars.discourse-cdn.com/v4/letter/u/eb9ed0/32.png) [@uniquename](https://discuss.elastic.co/u/uniquename)
#### Post date: [January 21, 2020, 2:20am UTC](https://discuss.elastic.co/t/how-to-query-for-changes/215812/1 "2020-01-21T02:20:56Z")

</div>

Hi,  
I am looking for a way to query for changes in my elasticsearch documents. I have devices which periodically check in with their on/off status so my document will look something like this:

@timestamp - January 21st 2020, 15:15:33.459  
on\_status - "on"  
error - 2

How can I write a query which will return all the documents where the values for on\_status or error have changed from their previous values (ie. the device turned off)? What about if I want to list every time error went up from 0/back down to 0?

---

<div class="post-metadata">

### Author: ![Magnus\_Kessler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_kessler/32/42001_2.png) [@Magnus\_Kessler](https://discuss.elastic.co/u/Magnus_Kessler)
#### Post date: [January 21, 2020, 7:05am UTC](https://discuss.elastic.co/t/how-to-query-for-changes/215812/2 "2020-01-21T07:05:35Z")

</div>

This is not possible in the way you describe. Elasticsesarch does not track changes to documents.

However, you could probably use a different approach: Treat each status change as a separate document. Then create an aggregation query over a recent time frame that aggregates by device ID. For each of the devices, aggregate on the status field. Devices that have more than one status value have switched state. A top-hits aggregation (sorted by date) would return the current status, and you can infer the switch direction from there.

---

<div class="post-metadata">

### Author: ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)
#### Post date: [January 21, 2020, 11:07am UTC](https://discuss.elastic.co/t/how-to-query-for-changes/215812/3 "2020-01-21T11:07:37Z")

</div>

How do you control your document id?  
If you can control the document ID, you could do a simple trick with this by using @timestamp.

- You update the document only if you have the device up. All other devices will not get the update and therefore you can assume that their status is down. So if the device will not check in, it will not update the document and you can query for something that is for example: now-2h/now-4h.

- Another way is just to create two indexes, one for devices up, another for devices down.

- or you create array with the document check-in and its status and you can retain the history

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 18, 2020, 11:07am UTC](https://discuss.elastic.co/t/how-to-query-for-changes/215812/4 "2020-02-18T11:07:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
