# Incongruencies between queries and slow logs

**URL:** <https://discuss.elastic.co/t/incongruencies-between-queries-and-slow-logs/178053>\
**Category:** Elasticsearch\
**Created:** [April 23, 2019, 2:18pm UTC](https://discuss.elastic.co/t/incongruencies-between-queries-and-slow-logs/178053 "2019-04-23T14:18:06Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Manofwax](https://avatars.discourse-cdn.com/v4/letter/m/59ef9b/32.png) [@Manofwax](https://discuss.elastic.co/u/Manofwax)\
**Post date:** [April 23, 2019, 2:18pm UTC](https://discuss.elastic.co/t/incongruencies-between-queries-and-slow-logs/178053/1 "2019-04-23T14:18:06Z")

</div>

Hello,  
I'm running elasticsearch 6.5.4 with only one node and I've configured slow log to log all queries. I've found some incongruencies between the query I'm running and the one that is logged in `slow log`. Examples:

```auto
GET /network-*/_search
{
  "size": 0,
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "now-1d/d",
              "lt": "now/d"
            }
          }
        },
        {
          "term": {
            "src_addr": "1.1.1.1"
          }
        }
      ]
    }
  }
}

```

Result:

```auto
{
  "took" : 2,
  "timed_out" : false,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : 5,
    "max_score" : 0.0,
    "hits" : []
  }
}

```

Logged query:

```auto
{"size":0,"query":{"match_none":{"boost":1.0}}}

```

Query:

```auto
GET /network-*/_search
{
  "size": 0,
  "query": {
    "bool": {
      "filter": [
        {
          "range": {
            "@timestamp": {
              "gte": "now-300m",
              "lt": "now"
            }
          }
        },
        {
          "term": {
            "src_addr": "1.1.1.1"
          }
        }
      ]
    }
  }
}

```

Result:

```auto
{
  "took" : 3,
  "timed_out" : false,
  "_shards" : {
    "total" : 5,
    "successful" : 5,
    "skipped" : 0,
    "failed" : 0
  },
  "hits" : {
    "total" : 5,
    "max_score" : 0.0,
    "hits" : []
  }
}

```

Logged Query:

```auto
{"size":0,"query":{"bool":{"filter":[{"range":{"@timestamp":{"from":"now-300m","to":"now","include_lower":true,"include_upper":false,"boost":1.0}}},{"term":{"src_addr":{"value":"1.1.1.1","boost":1.0}}}],"adjust_pure_negative":true,"boost":1.0}}}

```

How is that possible? I'm doing something wrong?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2019, 2:18pm UTC](https://discuss.elastic.co/t/incongruencies-between-queries-and-slow-logs/178053/2 "2019-05-21T14:18:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
