# Query and return all of the results

**URL:** <https://discuss.elastic.co/t/query-and-return-all-of-the-results/54783>\
**Category:** Elasticsearch\
**Created:** [July 5, 2016, 9:47pm UTC](https://discuss.elastic.co/t/query-and-return-all-of-the-results/54783 "2016-07-05T21:47:58Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![rheng](https://avatars.discourse-cdn.com/v4/letter/r/ccd318/32.png) [@rheng](https://discuss.elastic.co/u/rheng)\
**Post date:** [July 5, 2016, 9:47pm UTC](https://discuss.elastic.co/t/query-and-return-all-of-the-results/54783/1 "2016-07-05T21:47:58Z")

</div>

I'm trying to query elasticsearch to return all the index data between say july 3 and july 4.

I issued the query and it returned a total hits of 14003. I know the default value it returns is 10, and i can set the default settings up to 10000 being returned.

But If the total hits is 14003 and the max return value is only 10000, how could i get the remaining 4003 values.

I tried using the from/size: so i tried "from" : 10001 , "size" : 14003

but got the error stating that the size was too big.

Any ideas?

---

<div class="post-metadata">

**Author:** ![jasontedor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jasontedor/32/66992_2.png) [@jasontedor](https://discuss.elastic.co/u/jasontedor)\
**Post date:** [July 6, 2016, 2:33am UTC](https://discuss.elastic.co/t/query-and-return-all-of-the-results/54783/2 "2016-07-06T02:33:40Z")

</div>

You can use the [scroll API](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-scroll.html).

---

<div class="post-metadata">

**Author:** ![rheng](https://avatars.discourse-cdn.com/v4/letter/r/ccd318/32.png) [@rheng](https://discuss.elastic.co/u/rheng)\
**Post date:** [July 6, 2016, 5:00am UTC](https://discuss.elastic.co/t/query-and-return-all-of-the-results/54783/3 "2016-07-06T05:00:55Z")

</div>

Thanks, i tried the scroll and i can't get it to return all of it as well. i can't get it to return a large number of results or even the all the results as mentioned in the document. I get pages of it. I want everything in one shot. Maybe i don't have the correct syntax

curl -XGET '10.40.163.67:9200/sn\_index\_data/sn-node2/\_search?scroll=10m&pretty' -d '{  
"query": {  
"filtered": {  
"query": {  
"match\_all": {}  
},  
"filter": {  
"range": {  
"audit\_info.last\_accessed": {  
"gte": "2016-06-29T15:00:00",  
"lte": "2016-06-29T16:00:00"  
}  
}  
}  
}  
}  
}  
'

After running the initial query, i see (below), so i'm expecting 905 indices

"hits" : {  
"total" : 905,

Then after i get the scroll id i call

curl -XGET '10.40.163.67:9200/\_search/scroll' -d'  
{  
"scroll" : "10m",  
"scroll\_id" : "cXVlcnlUaGVuRmV0Y2g7NTs2NzkxOjBCYURadjJVVDZhTG5heVJndzEyV1E7Njc5MDowQmFEWnYyVVQ2YUxuYXlSZ3cxMldROzI0OTgxNDpTVTR1RXgwUVNXcVJXTV9HOVpCdlZnOzI0OTgxNTpTVTR1RXgwUVNXcVJXTV9HOVpCdlZnOzI0OTgxNjpTVTR1RXgwUVNXcVJXTV9HOVpCdlZnOzA7"  
}  
'

---

<div class="post-metadata">

**Author:** ![rheng](https://avatars.discourse-cdn.com/v4/letter/r/ccd318/32.png) [@rheng](https://discuss.elastic.co/u/rheng)\
**Post date:** [July 6, 2016, 5:44am UTC](https://discuss.elastic.co/t/query-and-return-all-of-the-results/54783/4 "2016-07-06T05:44:05Z")

</div>

Figured it out.

curl -XGET '10.40.163.67:9200/sn\_index\_data/sn-node2/\_search?scroll=10m&size=905' -d '{

does the trick.

---

<div class="post-metadata">

**Author:** ![nik9000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nik9000/32/44947_2.png) [@nik9000](https://discuss.elastic.co/u/nik9000)\
**Post date:** [July 6, 2016, 10:52am UTC](https://discuss.elastic.co/t/query-and-return-all-of-the-results/54783/5 "2016-07-06T10:52:27Z")

</div>

It is inefficient to just set the size to something huge. 905 isn't huge.  
For that many docs you don't need to scroll. If you had tens of thousands  
you'd need to scroll. You still set size to 1000 or 5000 or something, but  
you have to deal with the pages of results.

Elasticsearch doesn't support streaming the results back which is the only  
way you'd be able to request and get them all back in one response.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:37pm UTC](https://discuss.elastic.co/t/query-and-return-all-of-the-results/54783/6 "2017-07-05T22:37:41Z")

</div>


