# How to query for most recent entry?

**URL:** <https://discuss.elastic.co/t/how-to-query-for-most-recent-entry/687>\
**Category:** Elasticsearch\
**Created:** [May 14, 2015, 1:26pm UTC](https://discuss.elastic.co/t/how-to-query-for-most-recent-entry/687 "2015-05-14T13:26:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![JeremyinNC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremyinnc/32/44868_2.png) [@JeremyinNC](https://discuss.elastic.co/u/JeremyinNC)\
**Post date:** [May 14, 2015, 1:26pm UTC](https://discuss.elastic.co/t/how-to-query-for-most-recent-entry/687/1 "2015-05-14T13:26:11Z")

</div>

Sorry if this is a dumb question, we're using ES for lots of different things across our environment. I am the infrastructure guy and one of the things I am tasked with is monitoring functionality. What I would like to know is:

How do I query for the timestamp of the most recent entry for a specific type - for instance we're reading STOMP auditing messages from our message queue servers into a \_type=mq-message. How do I query either for the most recent entries timestamp or just query for X in the last 5 min.

I am trying the following but I am failing...

```
  curl -XGET http://localhost:9200/logstash-2015.05.14/_search 
 {
    "query": {
        "filtered": {
            "query": {
                "match_all": {}
            },
            "filter": {
                "term": {
                    "_type": "mq-message"
                }
            },
            "range": {
                "timestamp": {
                    "gt": "now-1h"
                }
            }
        }
    }
}

```

It says "ElasticsearchParseException[Expected field name but got START\_OBJECT "range"

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [May 14, 2015, 1:36pm UTC](https://discuss.elastic.co/t/how-to-query-for-most-recent-entry/687/2 "2015-05-14T13:36:49Z")

</div>

You need to put the range within the `filter` block. because you will then have multiple clauses in your `filter` object you will need to combine them using a `bool` query. Try doing the following:

```json
curl -XGET http://localhost:9200/logstash-2015.05.14/_search
{
  "query": {
    "filtered": {
      "query": {
        "match_all": {}
      },
      "filter": {
        "bool": {
          "should": [
            {
              "term": {
                "_type": "mq-message"
              }
            },
            {
              "range": {
                "timestamp": {
                  "gt": "now-1h"
                }
              }
            }
          ]
        }
      }
    }
  }
}

```

Note that you can also filter the search to a specific type in the URL so the above is equivalent to:

```json
curl -XGET http://localhost:9200/logstash-2015.05.14/mq-message/_search
{
  "query": {
    "filtered": {
      "query": {
        "match_all": {}
      },
      "filter": {
        "range": {
          "timestamp": {
            "gt": "now-1h"
          }
        }
      }
    }
  }
}

```

Hope that helps.

---

<div class="post-metadata">

**Author:** ![JeremyinNC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremyinnc/32/44868_2.png) [@JeremyinNC](https://discuss.elastic.co/u/JeremyinNC)\
**Post date:** [May 14, 2015, 1:52pm UTC](https://discuss.elastic.co/t/how-to-query-for-most-recent-entry/687/3 "2015-05-14T13:52:14Z")

</div>

Fantastic, thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:06pm UTC](https://discuss.elastic.co/t/how-to-query-for-most-recent-entry/687/5 "2017-07-05T22:06:44Z")

</div>


