# How to retrieve only latest index

**URL:** <https://discuss.elastic.co/t/how-to-retrieve-only-latest-index/268264>\
**Category:** Elasticsearch\
**Created:** [March 24, 2021, 8:10pm UTC](https://discuss.elastic.co/t/how-to-retrieve-only-latest-index/268264 "2021-03-24T20:10:23Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![harper\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harper_s/32/86061_2.png) [@harper\_S](https://discuss.elastic.co/u/harper_S)\
**Post date:** [March 24, 2021, 8:10pm UTC](https://discuss.elastic.co/t/how-to-retrieve-only-latest-index/268264/1 "2021-03-24T20:10:23Z")

</div>

I have created a python api which will accept the \*.json file.

for ex: abc.json

```auto
{
    "service_name": "httpd",
    "service_status": "DOWN",
    "host_name": "host1",
    "time": "1616600149.014236"
}

```

and, push the data to the ES using below python api.

```auto
@app.route('/add', methods=['POST']) def insert_data():
    #directory = '/home/user'
    dir = os.getcwd()
    os.chdir(dir)
    i = 1
    #This function will read all the json payload in the given dir and upload to ES.
    for filename in os.listdir(dir):
        if filename.endswith(".json"):
            f = open(filename)
            status_content = f.read()
            # Send the data into es
            result=(es.index(index='svc_index', ignore=400, doc_type='doc',
            id=i, body=json.loads(status_content)))
            i = i + 1
            print("result")

    return jsonify(result)

```

Output:

```auto
{
        "_id": "4", 
        "_index": "svc_index", 
        "_score": 1.0, 
        "_source": {
          "host_name": "host1", 
          "service_name": "httpd", 
          "service_status": "DOWN", 
          "time": "1616600143.5427265"
        }, 
        "_type": "doc"
      },

```

Since timestamp is being stored as string, sorting is not working. I wanted to bring the latest result on top. Could anyone please help into this.

Thanks!!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 24, 2021, 8:21pm UTC](https://discuss.elastic.co/t/how-to-retrieve-only-latest-index/268264/2 "2021-03-24T20:21:21Z")

</div>

Welcome to our community! 😃

> [@harper\_S](#):
>
> Since timestamp is being stored as string

Which one is the timestamp?

---

<div class="post-metadata">

**Author:** ![harper\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harper_s/32/86061_2.png) [@harper\_S](https://discuss.elastic.co/u/harper_S)\
**Post date:** [March 24, 2021, 8:49pm UTC](https://discuss.elastic.co/t/how-to-retrieve-only-latest-index/268264/3 "2021-03-24T20:49:12Z")

</div>

Thanks Warkolm.

I have updated the time field to store in json file only in time format not in str.  
"time": 1616600143.5427265

and, still with the following code, when I am retrieving the latest result with desc order@time. it's not working.

```
result = es.search(index="svc_index", doc_type="doc", sort='time:desc', body={"query": {"match": {"service_name": query}}}, size=1)

```

Thanks!!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 24, 2021, 8:50pm UTC](https://discuss.elastic.co/t/how-to-retrieve-only-latest-index/268264/4 "2021-03-24T20:50:12Z")

</div>

Ideally you would translate that to a proper time format so that you can sort on it. Is that possible?

---

<div class="post-metadata">

**Author:** ![harper\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harper_s/32/86061_2.png) [@harper\_S](https://discuss.elastic.co/u/harper_S)\
**Post date:** [March 24, 2021, 8:53pm UTC](https://discuss.elastic.co/t/how-to-retrieve-only-latest-index/268264/5 "2021-03-24T20:53:39Z")

</div>

see , the timestamp of this file

[azureuser@harpr-mac]$ cat httpd-status-1616618301.5598042.json  
{  
"service\_name": "httpd",  
"service\_status": "DOWN",  
"host\_name": "host1",  
"time": 1616618301.5458138  
}

and with the following es result.

```
azureuser@harpr-mac]$ curl -X GET http://127.0.0.1:5000/healthcheck/httpd
{
  "_shards": {
    "failed": 0, 
    "skipped": 0, 
    "successful": 1, 
    "total": 1
  }, 
  "hits": {
    "hits": [
      {
        "_id": "4", 
        "_index": "svc_index", 
        "_score": null, 
        "_source": {
          "host_name": "host1", 
          "service_name": "httpd", 
          "service_status": "DOWN", 
          "time": 1616618210.7548866
        }, 
        "_type": "doc", 
        "sort": [
          1616618240.0
        ]
      }
    ], 
    "max_score": null, 
    "total": {
      "relation": "eq", 
      "value": 5
    }
  }, 
  "timed_out": false, 
  "took": 1
}
```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [March 24, 2021, 8:57pm UTC](https://discuss.elastic.co/t/how-to-retrieve-only-latest-index/268264/6 "2021-03-24T20:57:38Z")

</div>

That is not a valid timestamp for Elasticsearch, it's just a number. You will want it to be something like [Date field type | Elasticsearch Reference [7.12] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/date.html) for Elasticsearch to be able to translate that into UTC and then sort on.

---

<div class="post-metadata">

**Author:** ![harper\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harper_s/32/86061_2.png) [@harper\_S](https://discuss.elastic.co/u/harper_S)\
**Post date:** [March 24, 2021, 9:06pm UTC](https://discuss.elastic.co/t/how-to-retrieve-only-latest-index/268264/7 "2021-03-24T21:06:20Z")

</div>

> [@harper\_S](#):
>
> 1616618301

Agreed, its treating it as number, but still the latest file has greater timestamp 1616618301 than es result 1616618210.

If I use datetime in python to store the value in json, it give serializable error. I need to convert it to string first then in ES mapping which is not working through python script.

---

<div class="post-metadata">

**Author:** ![harper\_S](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/harper_s/32/86061_2.png) [@harper\_S](https://discuss.elastic.co/u/harper_S)\
**Post date:** [March 24, 2021, 10:51pm UTC](https://discuss.elastic.co/t/how-to-retrieve-only-latest-index/268264/8 "2021-03-24T22:51:30Z")

</div>

I have found the solution.

Use the following sort function with mode=max.

```auto
result = es.search(index="svc_index", doc_type="doc", body={"query": {"match": {"service_name": query}},"sort":{"time": {'order': 'desc', 'mode':'max'}}}, size=1)

```

Thanks for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 21, 2021, 10:51pm UTC](https://discuss.elastic.co/t/how-to-retrieve-only-latest-index/268264/9 "2021-04-21T22:51:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
