# Need some help with a range query

**URL:** <https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854>\
**Category:** Elasticsearch\
**Created:** [November 11, 2011, 11:28pm UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854 "2011-11-11T23:28:41Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![electic](https://avatars.discourse-cdn.com/v4/letter/e/ecccb3/32.png) [@electic](https://discuss.elastic.co/u/electic)\
**Post date:** [November 11, 2011, 11:28pm UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/1 "2011-11-11T23:28:41Z")

</div>

I have a document like this:

curl -XPOST 192.168.8.231:9200/documents -d '{  
"settings" : {  
"number\_of\_shards" : 20,  
"number\_of\_replicas" : 0  
},  
"mappings" : {  
"document" : {  
"\_source" : { "enabled" : false },  
"properties" : {  
"record\_id" : { "type" : "string", "index" :  
"analyzed", "store" : "no" },  
"platform" : { "type" : "string", "index" :  
"analyzed", "store" : "no" },  
"tags" : { "type" : "string", "index" : "analyzed",  
"store" : "no" },  
"utimestamp" : { "type" : "long", "index" :  
"analyzed", "store" : "no" },  
"created\_at" : { "type" : "date", "index" :  
"analyzed", "store" : "no" }  
}  
}  
}  
}'

and I am trying to do a range query for records over a certain date:

curl -XGET 192.168.8.231:9200/documents/\_search -d '{

```
"query" : {
    "term" : { "tags" : "ass" },
    "fitler" : {
        "range" : {
            "created_at" : {
                "gte" : 1321050744
            }
        }
    }
}

```

}'

For the sake of simplicity, I have gone ahead and put a utimestamp and  
also a created at in the format of: %Y%m%dT%H:%M:%S.%i. When I try  
running the above range query, it gives an error, What is the proper  
syntax to do a range query? Any help is appreciated!

---

<div class="post-metadata">

**Author:** ![vinny](https://avatars.discourse-cdn.com/v4/letter/v/b9e5f3/32.png) [@vinny](https://discuss.elastic.co/u/vinny)\
**Post date:** [November 12, 2011, 4:26am UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/2 "2011-11-12T04:26:23Z")

</div>

Was the ranger filter copied exactly from what you were working from? I  
ask because "filter" is misspelled. Also, not sure if you want to use the  
created\_at for the filter, I would think you would want to use the  
utimestamp.

---

<div class="post-metadata">

**Author:** ![egaumer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/egaumer/32/2365_2.png) [@egaumer](https://discuss.elastic.co/u/egaumer)\
**Post date:** [November 12, 2011, 4:52am UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/3 "2011-11-12T04:52:05Z")

</div>

You should use a filteredQuery.

{  
"filtered" : {  
"query" : {  
"term" : { "tags" : "ass" }  
},  
"filter" : {  
"numeric\_range" : {  
"created\_at" : {  
"gte" : 1321050744  
}  
}  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![electic](https://avatars.discourse-cdn.com/v4/letter/e/ecccb3/32.png) [@electic](https://discuss.elastic.co/u/electic)\
**Post date:** [November 12, 2011, 6:58pm UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/4 "2011-11-12T18:58:37Z")

</div>

Thanks everyone for your help! So I have one more question. So this is  
what I have now:

curl -XGET 192.168.8.231:9200/documents/\_search -d '{

```
"query" : {
    "filtered" : {
        "query":{"match_all":{}},
        "filter" : {
            "and" : [{"term" : {"tags" : "chat car"}}, {"range" :

```

{"utimestamp" : {"gte" : 1321085190}}}]  
},  
"sort" : {"created\_at" : "desc" }  
},  
"size" : 500  
}  
}'

and it works if you do it for one keyword. However, what if you want  
two keywords, say, "chat car" which there are records for but it  
returns nothing back. What is the best way to to do that?

On Nov 11, 8:52 pm, egaumer [egau...@gmail.com](mailto:egau...@gmail.com) wrote:

> You should use a filteredQuery.
> 
> {  
> "filtered" : {  
> "query" : {  
> "term" : { "tags" : "ass" }  
> },  
> "filter" : {  
> "numeric\_range" : {  
> "created\_at" : {  
> "gte" : 1321050744  
> }  
> }  
> }  
> }
> 
> }

---

<div class="post-metadata">

**Author:** ![electic](https://avatars.discourse-cdn.com/v4/letter/e/ecccb3/32.png) [@electic](https://discuss.elastic.co/u/electic)\
**Post date:** [November 12, 2011, 7:04pm UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/5 "2011-11-12T19:04:04Z")

</div>

I think I got it, if anyone else needs help:

curl -XGET 192.168.8.231:9200/documents/\_search -d '{

```
"query" : {
    "filtered" : {
        "query":{
            "query_string" : {
                "query" : "chat car",
                "default_operator" : "AND"

            }
        },
        "filter" : {
            "and" : [{"range" : {"utimestamp" : {"gte" :

```

1321085190}}}]  
},  
"sort" : {"created\_at" : "desc" }  
},  
"size" : 500  
}  
}'

On Nov 12, 10:58 am, electic [elec...@gmail.com](mailto:elec...@gmail.com) wrote:

> Thanks everyone for your help! So I have one more question. So this is  
> what I have now:
> 
> curl -XGET 192.168.8.231:9200/documents/\_search -d '{
> 
> ```
> "query" : {
> "filtered" : {
> "query":{"match_all":{}},
> "filter" : {
> "and" : [{"term" : {"tags" : "chat car"}}, {"range" :
> 
> ```
> 
> {"utimestamp" : {"gte" : 1321085190}}}]  
> },  
> "sort" : {"created\_at" : "desc" }  
> },  
> "size" : 500  
> }  
> }'
> 
> and it works if you do it for one keyword. However, what if you want  
> two keywords, say, "chat car" which there are records for but it  
> returns nothing back. What is the best way to to do that?
> 
> On Nov 11, 8:52 pm, egaumer [egau...@gmail.com](mailto:egau...@gmail.com) wrote:
> 
> > You should use a filteredQuery.
> 
> > {  
> > "filtered" : {  
> > "query" : {  
> > "term" : { "tags" : "ass" }  
> > },  
> > "filter" : {  
> > "numeric\_range" : {  
> > "created\_at" : {  
> > "gte" : 1321050744  
> > }  
> > }  
> > }  
> > }
> 
> > }

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [November 13, 2011, 8:52am UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/6 "2011-11-13T08:52:29Z")

</div>

Btw, your sort is not on the correct level and size are not on the correct  
level, they should be on hte same level as the outermost "query".

On Sat, Nov 12, 2011 at 8:58 PM, electic [electic@gmail.com](mailto:electic@gmail.com) wrote:

> Thanks everyone for your help! So I have one more question. So this is  
> what I have now:
> 
> curl -XGET 192.168.8.231:9200/documents/\_search -d '{
> 
> "query" : {  
> "filtered" : {  
> "query":{"match\_all":{}},  
> "filter" : {  
> "and" : [{"term" : {"tags" : "chat car"}}, {"range" :  
> {"utimestamp" : {"gte" : 1321085190}}}]  
> },  
> "sort" : {"created\_at" : "desc" }  
> },  
> "size" : 500  
> }  
> }'
> 
> and it works if you do it for one keyword. However, what if you want  
> two keywords, say, "chat car" which there are records for but it  
> returns nothing back. What is the best way to to do that?
> 
> On Nov 11, 8:52 pm, egaumer [egau...@gmail.com](mailto:egau...@gmail.com) wrote:
> 
> > You should use a filteredQuery.
> > 
> > {  
> > "filtered" : {  
> > "query" : {  
> > "term" : { "tags" : "ass" }  
> > },  
> > "filter" : {  
> > "numeric\_range" : {  
> > "created\_at" : {  
> > "gte" : 1321050744  
> > }  
> > }  
> > }  
> > }
> > 
> > }

---

<div class="post-metadata">

**Author:** ![electic](https://avatars.discourse-cdn.com/v4/letter/e/ecccb3/32.png) [@electic](https://discuss.elastic.co/u/electic)\
**Post date:** [November 13, 2011, 11:44am UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/7 "2011-11-13T11:44:54Z")

</div>

Oh no, so it should be like this?

curl -XGET 192.168.8.231:9200/documents/\_search -d '{  
"query" : {  
"filtered" : {  
"query":{  
"query\_string" : {  
"query" : "chat car",  
"default\_operator" : "AND"  
},  
"sort" : {"created\_at" : "desc" }  
},  
"filter" : {  
"and" : [{"range" : {"utimestamp" : {"gte" :  
1321085190}}}]  
}  
},  
"size" : 500  
}  
}'

On Nov 13, 12:52 am, Shay Banon [kim...@gmail.com](mailto:kim...@gmail.com) wrote:

> Btw, your sort is not on the correct level and size are not on the correct  
> level, they should be on hte same level as the outermost "query".
> 
> On Sat, Nov 12, 2011 at 8:58 PM, electic [elec...@gmail.com](mailto:elec...@gmail.com) wrote:
> 
> > Thanks everyone for your help! So I have one more question. So this is  
> > what I have now:
> 
> > curl -XGET 192.168.8.231:9200/documents/\_search -d '{
> 
> > "query" : {  
> > "filtered" : {  
> > "query":{"match\_all":{}},  
> > "filter" : {  
> > "and" : [{"term" : {"tags" : "chat car"}}, {"range" :  
> > {"utimestamp" : {"gte" : 1321085190}}}]  
> > },  
> > "sort" : {"created\_at" : "desc" }  
> > },  
> > "size" : 500  
> > }  
> > }'
> 
> > and it works if you do it for one keyword. However, what if you want  
> > two keywords, say, "chat car" which there are records for but it  
> > returns nothing back. What is the best way to to do that?
> 
> > On Nov 11, 8:52 pm, egaumer [egau...@gmail.com](mailto:egau...@gmail.com) wrote:
> > 
> > > You should use a filteredQuery.
> 
> > > {  
> > > "filtered" : {  
> > > "query" : {  
> > > "term" : { "tags" : "ass" }  
> > > },  
> > > "filter" : {  
> > > "numeric\_range" : {  
> > > "created\_at" : {  
> > > "gte" : 1321050744  
> > > }  
> > > }  
> > > }  
> > > }
> 
> > > }

---

<div class="post-metadata">

**Author:** ![kimchy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kimchy/32/44952_2.png) [@kimchy](https://discuss.elastic.co/u/kimchy)\
**Post date:** [November 13, 2011, 1:34pm UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/8 "2011-11-13T13:34:21Z")

</div>

No, it should be on the same level as the top most query, the search  
request looks something like this:

{  
"query" : { ... },  
"size" : 100,  
"sort" : {...}  
}

On Sun, Nov 13, 2011 at 1:44 PM, electic [electic@gmail.com](mailto:electic@gmail.com) wrote:

> Oh no, so it should be like this?
> 
> curl -XGET 192.168.8.231:9200/documents/\_search -d '{  
> "query" : {  
> "filtered" : {  
> "query":{  
> "query\_string" : {  
> "query" : "chat car",  
> "default\_operator" : "AND"  
> },  
> "sort" : {"created\_at" : "desc" }  
> },  
> "filter" : {  
> "and" : [{"range" : {"utimestamp" : {"gte" :  
> 1321085190}}}]  
> }  
> },  
> "size" : 500  
> }  
> }'
> 
> On Nov 13, 12:52 am, Shay Banon [kim...@gmail.com](mailto:kim...@gmail.com) wrote:
> 
> > Btw, your sort is not on the correct level and size are not on the  
> > correct  
> > level, they should be on hte same level as the outermost "query".
> > 
> > On Sat, Nov 12, 2011 at 8:58 PM, electic [elec...@gmail.com](mailto:elec...@gmail.com) wrote:
> > 
> > > Thanks everyone for your help! So I have one more question. So this is  
> > > what I have now:
> > 
> > > curl -XGET 192.168.8.231:9200/documents/\_search -d '{
> > 
> > > "query" : {  
> > > "filtered" : {  
> > > "query":{"match\_all":{}},  
> > > "filter" : {  
> > > "and" : [{"term" : {"tags" : "chat car"}}, {"range" :  
> > > {"utimestamp" : {"gte" : 1321085190}}}]  
> > > },  
> > > "sort" : {"created\_at" : "desc" }  
> > > },  
> > > "size" : 500  
> > > }  
> > > }'
> > 
> > > and it works if you do it for one keyword. However, what if you want  
> > > two keywords, say, "chat car" which there are records for but it  
> > > returns nothing back. What is the best way to to do that?
> > 
> > > On Nov 11, 8:52 pm, egaumer [egau...@gmail.com](mailto:egau...@gmail.com) wrote:
> > > 
> > > > You should use a filteredQuery.
> > 
> > > > {  
> > > > "filtered" : {  
> > > > "query" : {  
> > > > "term" : { "tags" : "ass" }  
> > > > },  
> > > > "filter" : {  
> > > > "numeric\_range" : {  
> > > > "created\_at" : {  
> > > > "gte" : 1321050744  
> > > > }  
> > > > }  
> > > > }  
> > > > }
> > 
> > > > }

---

<div class="post-metadata">

**Author:** ![electic](https://avatars.discourse-cdn.com/v4/letter/e/ecccb3/32.png) [@electic](https://discuss.elastic.co/u/electic)\
**Post date:** [November 13, 2011, 11:23pm UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/9 "2011-11-13T23:23:58Z")

</div>

Thanks Shay. You are right. It was nested wrong. I have one more  
question for you guys. I have a query like this

(keyword1 | keyword2) keyword3

I am putting this into my query\_string-\>query part of the JSON with a  
default operator of AND. My guess is that the system is not  
recognizing the pipe symbol for some reason. How would I use the pipe  
symbol in the query?

On Nov 13, 5:34 am, Shay Banon [kim...@gmail.com](mailto:kim...@gmail.com) wrote:

> No, it should be on the same level as the top most query, the search  
> request looks something like this:
> 
> {  
> "query" : { ... },  
> "size" : 100,  
> "sort" : {...}
> 
> }  
> On Sun, Nov 13, 2011 at 1:44 PM, electic [elec...@gmail.com](mailto:elec...@gmail.com) wrote:
> 
> > Oh no, so it should be like this?
> 
> > curl -XGET 192.168.8.231:9200/documents/\_search -d '{  
> > "query" : {  
> > "filtered" : {  
> > "query":{  
> > "query\_string" : {  
> > "query" : "chat car",  
> > "default\_operator" : "AND"  
> > },  
> > "sort" : {"created\_at" : "desc" }  
> > },  
> > "filter" : {  
> > "and" : [{"range" : {"utimestamp" : {"gte" :  
> > 1321085190}}}]  
> > }  
> > },  
> > "size" : 500  
> > }  
> > }'
> 
> > On Nov 13, 12:52 am, Shay Banon [kim...@gmail.com](mailto:kim...@gmail.com) wrote:
> > 
> > > Btw, your sort is not on the correct level and size are not on the  
> > > correct  
> > > level, they should be on hte same level as the outermost "query".
> 
> > > On Sat, Nov 12, 2011 at 8:58 PM, electic [elec...@gmail.com](mailto:elec...@gmail.com) wrote:
> > > 
> > > > Thanks everyone for your help! So I have one more question. So this is  
> > > > what I have now:
> 
> > > > curl -XGET 192.168.8.231:9200/documents/\_search -d '{
> 
> > > > "query" : {  
> > > > "filtered" : {  
> > > > "query":{"match\_all":{}},  
> > > > "filter" : {  
> > > > "and" : [{"term" : {"tags" : "chat car"}}, {"range" :  
> > > > {"utimestamp" : {"gte" : 1321085190}}}]  
> > > > },  
> > > > "sort" : {"created\_at" : "desc" }  
> > > > },  
> > > > "size" : 500  
> > > > }  
> > > > }'
> 
> > > > and it works if you do it for one keyword. However, what if you want  
> > > > two keywords, say, "chat car" which there are records for but it  
> > > > returns nothing back. What is the best way to to do that?
> 
> > > > On Nov 11, 8:52 pm, egaumer [egau...@gmail.com](mailto:egau...@gmail.com) wrote:
> > > > 
> > > > > You should use a filteredQuery.
> 
> > > > > {  
> > > > > "filtered" : {  
> > > > > "query" : {  
> > > > > "term" : { "tags" : "ass" }  
> > > > > },  
> > > > > "filter" : {  
> > > > > "numeric\_range" : {  
> > > > > "created\_at" : {  
> > > > > "gte" : 1321050744  
> > > > > }  
> > > > > }  
> > > > > }  
> > > > > }
> 
> > > > > }

---

<div class="post-metadata">

**Author:** ![Gustavo\_Maia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_maia/32/2183_2.png) [@Gustavo\_Maia](https://discuss.elastic.co/u/Gustavo_Maia)\
**Post date:** [November 13, 2011, 11:52pm UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/10 "2011-11-13T23:52:51Z")

</div>

User term OR.

(keyword1 OR keyword2) keyword3

2011/11/13 electic [electic@gmail.com](mailto:electic@gmail.com):

> Thanks Shay. You are right. It was nested wrong. I have one more  
> question for you guys. I have a query like this
> 
> (keyword1 | keyword2) keyword3
> 
> I am putting this into my query\_string-\>query part of the JSON with a  
> default operator of AND. My guess is that the system is not  
> recognizing the pipe symbol for some reason. How would I use the pipe  
> symbol in the query?
> 
> On Nov 13, 5:34 am, Shay Banon [kim...@gmail.com](mailto:kim...@gmail.com) wrote:
> 
> > No, it should be on the same level as the top most query, the search  
> > request looks something like this:
> > 
> > {  
> > "query" : { ... },  
> > "size" : 100,  
> > "sort" : {...}
> > 
> > }  
> > On Sun, Nov 13, 2011 at 1:44 PM, electic [elec...@gmail.com](mailto:elec...@gmail.com) wrote:
> > 
> > > Oh no, so it should be like this?
> > 
> > > curl -XGET 192.168.8.231:9200/documents/\_search -d '{  
> > > "query" : {  
> > > "filtered" : {  
> > > "query":{  
> > > "query\_string" : {  
> > > "query" : "chat car",  
> > > "default\_operator" : "AND"  
> > > },  
> > > "sort" : {"created\_at" : "desc" }  
> > > },  
> > > "filter" : {  
> > > "and" : [{"range" : {"utimestamp" : {"gte" :  
> > > 1321085190}}}]  
> > > }  
> > > },  
> > > "size" : 500  
> > > }  
> > > }'
> > 
> > > On Nov 13, 12:52 am, Shay Banon [kim...@gmail.com](mailto:kim...@gmail.com) wrote:
> > > 
> > > > Btw, your sort is not on the correct level and size are not on the  
> > > > correct  
> > > > level, they should be on hte same level as the outermost "query".
> > 
> > > > On Sat, Nov 12, 2011 at 8:58 PM, electic [elec...@gmail.com](mailto:elec...@gmail.com) wrote:
> > > > 
> > > > > Thanks everyone for your help! So I have one more question. So this is  
> > > > > what I have now:
> > 
> > > > > curl -XGET 192.168.8.231:9200/documents/\_search -d '{
> > 
> > > > > "query" : {  
> > > > > "filtered" : {  
> > > > > "query":{"match\_all":{}},  
> > > > > "filter" : {  
> > > > > "and" : [{"term" : {"tags" : "chat car"}}, {"range" :  
> > > > > {"utimestamp" : {"gte" : 1321085190}}}]  
> > > > > },  
> > > > > "sort" : {"created\_at" : "desc" }  
> > > > > },  
> > > > > "size" : 500  
> > > > > }  
> > > > > }'
> > 
> > > > > and it works if you do it for one keyword. However, what if you want  
> > > > > two keywords, say, "chat car" which there are records for but it  
> > > > > returns nothing back. What is the best way to to do that?
> > 
> > > > > On Nov 11, 8:52 pm, egaumer [egau...@gmail.com](mailto:egau...@gmail.com) wrote:
> > > > > 
> > > > > > You should use a filteredQuery.
> > 
> > > > > > {  
> > > > > > "filtered" : {  
> > > > > > "query" : {  
> > > > > > "term" : { "tags" : "ass" }  
> > > > > > },  
> > > > > > "filter" : {  
> > > > > > "numeric\_range" : {  
> > > > > > "created\_at" : {  
> > > > > > "gte" : 1321050744  
> > > > > > }  
> > > > > > }  
> > > > > > }  
> > > > > > }
> > 
> > > > > > }

--  
Gustavo Maia

---

<div class="post-metadata">

**Author:** ![electic](https://avatars.discourse-cdn.com/v4/letter/e/ecccb3/32.png) [@electic](https://discuss.elastic.co/u/electic)\
**Post date:** [November 13, 2011, 11:54pm UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/11 "2011-11-13T23:54:12Z")

</div>

I know that but is there a way to support the pipe symbol as an OR?

On Nov 13, 3:52 pm, Gustavo Maia [gustavobbm...@gmail.com](mailto:gustavobbm...@gmail.com) wrote:

> User term OR.
> 
> (keyword1 OR keyword2) keyword3
> 
> 2011/11/13 electic [elec...@gmail.com](mailto:elec...@gmail.com):
> 
> > Thanks Shay. You are right. It was nested wrong. I have one more  
> > question for you guys. I have a query like this
> 
> > (keyword1 | keyword2) keyword3
> 
> > I am putting this into my query\_string-\>query part of the JSON with a  
> > default operator of AND. My guess is that the system is not  
> > recognizing the pipe symbol for some reason. How would I use the pipe  
> > symbol in the query?
> 
> > On Nov 13, 5:34 am, Shay Banon [kim...@gmail.com](mailto:kim...@gmail.com) wrote:
> > 
> > > No, it should be on the same level as the top most query, the search  
> > > request looks something like this:
> 
> > > {  
> > > "query" : { ... },  
> > > "size" : 100,  
> > > "sort" : {...}
> 
> > > }  
> > > On Sun, Nov 13, 2011 at 1:44 PM, electic [elec...@gmail.com](mailto:elec...@gmail.com) wrote:
> > > 
> > > > Oh no, so it should be like this?
> 
> > > > curl -XGET 192.168.8.231:9200/documents/\_search -d '{  
> > > > "query" : {  
> > > > "filtered" : {  
> > > > "query":{  
> > > > "query\_string" : {  
> > > > "query" : "chat car",  
> > > > "default\_operator" : "AND"  
> > > > },  
> > > > "sort" : {"created\_at" : "desc" }  
> > > > },  
> > > > "filter" : {  
> > > > "and" : [{"range" : {"utimestamp" : {"gte" :  
> > > > 1321085190}}}]  
> > > > }  
> > > > },  
> > > > "size" : 500  
> > > > }  
> > > > }'
> 
> > > > On Nov 13, 12:52 am, Shay Banon [kim...@gmail.com](mailto:kim...@gmail.com) wrote:
> > > > 
> > > > > Btw, your sort is not on the correct level and size are not on the  
> > > > > correct  
> > > > > level, they should be on hte same level as the outermost "query".
> 
> > > > > On Sat, Nov 12, 2011 at 8:58 PM, electic [elec...@gmail.com](mailto:elec...@gmail.com) wrote:
> > > > > 
> > > > > > Thanks everyone for your help! So I have one more question. So this is  
> > > > > > what I have now:
> 
> > > > > > curl -XGET 192.168.8.231:9200/documents/\_search -d '{
> 
> > > > > > "query" : {  
> > > > > > "filtered" : {  
> > > > > > "query":{"match\_all":{}},  
> > > > > > "filter" : {  
> > > > > > "and" : [{"term" : {"tags" : "chat car"}}, {"range" :  
> > > > > > {"utimestamp" : {"gte" : 1321085190}}}]  
> > > > > > },  
> > > > > > "sort" : {"created\_at" : "desc" }  
> > > > > > },  
> > > > > > "size" : 500  
> > > > > > }  
> > > > > > }'
> 
> > > > > > and it works if you do it for one keyword. However, what if you want  
> > > > > > two keywords, say, "chat car" which there are records for but it  
> > > > > > returns nothing back. What is the best way to to do that?
> 
> > > > > > On Nov 11, 8:52 pm, egaumer [egau...@gmail.com](mailto:egau...@gmail.com) wrote:
> > > > > > 
> > > > > > > You should use a filteredQuery.
> 
> > > > > > > {  
> > > > > > > "filtered" : {  
> > > > > > > "query" : {  
> > > > > > > "term" : { "tags" : "ass" }  
> > > > > > > },  
> > > > > > > "filter" : {  
> > > > > > > "numeric\_range" : {  
> > > > > > > "created\_at" : {  
> > > > > > > "gte" : 1321050744  
> > > > > > > }  
> > > > > > > }  
> > > > > > > }  
> > > > > > > }
> 
> > > > > > > }
> 
> --  
> Gustavo Maia

---

<div class="post-metadata">

**Author:** ![Gustavo\_Maia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gustavo_maia/32/2183_2.png) [@Gustavo\_Maia](https://discuss.elastic.co/u/Gustavo_Maia)\
**Post date:** [November 13, 2011, 11:55pm UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/12 "2011-11-13T23:55:23Z")

</div>

I don;t know i only use symbol OR.

2011/11/13 electic [electic@gmail.com](mailto:electic@gmail.com):

> I know that but is there a way to support the pipe symbol as an OR?
> 
> On Nov 13, 3:52 pm, Gustavo Maia [gustavobbm...@gmail.com](mailto:gustavobbm...@gmail.com) wrote:
> 
> > User term OR.
> > 
> > (keyword1 OR keyword2) keyword3
> > 
> > 2011/11/13 electic [elec...@gmail.com](mailto:elec...@gmail.com):
> > 
> > > Thanks Shay. You are right. It was nested wrong. I have one more  
> > > question for you guys. I have a query like this
> > 
> > > (keyword1 | keyword2) keyword3
> > 
> > > I am putting this into my query\_string-\>query part of the JSON with a  
> > > default operator of AND. My guess is that the system is not  
> > > recognizing the pipe symbol for some reason. How would I use the pipe  
> > > symbol in the query?
> > 
> > > On Nov 13, 5:34 am, Shay Banon [kim...@gmail.com](mailto:kim...@gmail.com) wrote:
> > > 
> > > > No, it should be on the same level as the top most query, the search  
> > > > request looks something like this:
> > 
> > > > {  
> > > > "query" : { ... },  
> > > > "size" : 100,  
> > > > "sort" : {...}
> > 
> > > > }  
> > > > On Sun, Nov 13, 2011 at 1:44 PM, electic [elec...@gmail.com](mailto:elec...@gmail.com) wrote:
> > > > 
> > > > > Oh no, so it should be like this?
> > 
> > > > > curl -XGET 192.168.8.231:9200/documents/\_search -d '{  
> > > > > "query" : {  
> > > > > "filtered" : {  
> > > > > "query":{  
> > > > > "query\_string" : {  
> > > > > "query" : "chat car",  
> > > > > "default\_operator" : "AND"  
> > > > > },  
> > > > > "sort" : {"created\_at" : "desc" }  
> > > > > },  
> > > > > "filter" : {  
> > > > > "and" : [{"range" : {"utimestamp" : {"gte" :  
> > > > > 1321085190}}}]  
> > > > > }  
> > > > > },  
> > > > > "size" : 500  
> > > > > }  
> > > > > }'
> > 
> > > > > On Nov 13, 12:52 am, Shay Banon [kim...@gmail.com](mailto:kim...@gmail.com) wrote:
> > > > > 
> > > > > > Btw, your sort is not on the correct level and size are not on the  
> > > > > > correct  
> > > > > > level, they should be on hte same level as the outermost "query".
> > 
> > > > > > On Sat, Nov 12, 2011 at 8:58 PM, electic [elec...@gmail.com](mailto:elec...@gmail.com) wrote:
> > > > > > 
> > > > > > > Thanks everyone for your help! So I have one more question. So this is  
> > > > > > > what I have now:
> > 
> > > > > > > curl -XGET 192.168.8.231:9200/documents/\_search -d '{
> > 
> > > > > > > "query" : {  
> > > > > > > "filtered" : {  
> > > > > > > "query":{"match\_all":{}},  
> > > > > > > "filter" : {  
> > > > > > > "and" : [{"term" : {"tags" : "chat car"}}, {"range" :  
> > > > > > > {"utimestamp" : {"gte" : 1321085190}}}]  
> > > > > > > },  
> > > > > > > "sort" : {"created\_at" : "desc" }  
> > > > > > > },  
> > > > > > > "size" : 500  
> > > > > > > }  
> > > > > > > }'
> > 
> > > > > > > and it works if you do it for one keyword. However, what if you want  
> > > > > > > two keywords, say, "chat car" which there are records for but it  
> > > > > > > returns nothing back. What is the best way to to do that?
> > 
> > > > > > > On Nov 11, 8:52 pm, egaumer [egau...@gmail.com](mailto:egau...@gmail.com) wrote:
> > > > > > > 
> > > > > > > > You should use a filteredQuery.
> > 
> > > > > > > > {  
> > > > > > > > "filtered" : {  
> > > > > > > > "query" : {  
> > > > > > > > "term" : { "tags" : "ass" }  
> > > > > > > > },  
> > > > > > > > "filter" : {  
> > > > > > > > "numeric\_range" : {  
> > > > > > > > "created\_at" : {  
> > > > > > > > "gte" : 1321050744  
> > > > > > > > }  
> > > > > > > > }  
> > > > > > > > }  
> > > > > > > > }
> > 
> > > > > > > > }
> > 
> > --  
> > Gustavo Maia

--  
Gustavo Maia

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 3:48am UTC](https://discuss.elastic.co/t/need-some-help-with-a-range-query/5854/13 "2017-07-06T03:48:50Z")

</div>


