# Query help request

**URL:** <https://discuss.elastic.co/t/query-help-request/82425>\
**Category:** Elasticsearch\
**Created:** [April 14, 2017, 3:31pm UTC](https://discuss.elastic.co/t/query-help-request/82425 "2017-04-14T15:31:46Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kryten](https://avatars.discourse-cdn.com/v4/letter/k/58956e/32.png) [@Kryten](https://discuss.elastic.co/u/Kryten)\
**Post date:** [April 14, 2017, 3:31pm UTC](https://discuss.elastic.co/t/query-help-request/82425/1 "2017-04-14T15:31:46Z")

</div>

Hi,

Using ES 5.x ..

Would appreciate some assistance with a filtered query, please.

I need to query my data using the "exists" filter to retrieve all documents where a specified field exists but I need it to be filtered by the last three days. Here is what I have:

```
{
      "filter": {
        "bool": {
          "must": [
            {
              "exists": {
                "field": "exceptioncapture"
              }
            },
            {
              "range": {
                "@timestamp": {
                  "gt": "now",
                  "lt": "now-3d"
    			}
              }
            }
          ]
        }
      }
    }

```

I am getting back:

```
{
	"took": 260,
	"timed_out": false,
	"_shards": {
		"total": 55,
		"successful": 55,
		"failed": 0
	},
	"hits": {
		"total": 0,
		"max_score": null,
		"hits": []
	}
}

```

But no actual documents. I know the documents are there as running a query like:

```
{
	"_source":["exceptioncapture","message","@timestamp"],
    "filter": {
        "exists": {
         "field": "exceptioncapture"
         }
    },
    "size": 10,
    "sort": [
    {
        "@timestamp": {
        "order": "desc"
        }
    }
    ]
}

```

Actually returns documents.

Would really appreciate any help with how to accomplish this seemingly simple query.

---

<div class="post-metadata">

**Author:** ![s1monw](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/s1monw/32/3637_2.png) [@s1monw](https://discuss.elastic.co/u/s1monw)\
**Post date:** [April 21, 2017, 7:43am UTC](https://discuss.elastic.co/t/query-help-request/82425/2 "2017-04-21T07:43:47Z")

</div>

> [@Kryten](#):
>
> "range": {  
> "@timestamp": {  
> "gt": "now",  
> "lt": "now-3d"  
> }

I think you need to swap `gt` and `lt` ...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2017, 7:50am UTC](https://discuss.elastic.co/t/query-help-request/82425/3 "2017-05-19T07:50:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
