# Query items by time stamp not working

**URL:** <https://discuss.elastic.co/t/query-items-by-time-stamp-not-working/77229>\
**Category:** Elasticsearch\
**Created:** [March 2, 2017, 10:20pm UTC](https://discuss.elastic.co/t/query-items-by-time-stamp-not-working/77229 "2017-03-02T22:20:42Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ben\_Hoffman](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Ben\_Hoffman](https://discuss.elastic.co/u/Ben_Hoffman)\
**Post date:** [March 2, 2017, 10:20pm UTC](https://discuss.elastic.co/t/query-items-by-time-stamp-not-working/77229/1 "2017-03-02T22:20:42Z")

</div>

So I want to get all events since a certain time, for example since `"2017-03-02T21:56:53.033Z"`.

I made a `runtime_timestamp` field that just copies the `@timestamp` field, because I am parsing this data into C# and `@` symbols don't play nice in there.

Here is my Logstash filter for that, which DOES work. I know this for a fact.

```
 filter {
    mutate {
            add_field => ["runtime_timestamp", "%{@timestamp}"]

    }
}

```

Here is the what I have now, that does not work.

```
{
 "query": {
 "range": {
  "runtime_timestamp": 
    "2017-03-02T21:56:53.033Z"
}}},
"_source": {
"includes": [
  "runtime_timestamp",
  "id_orig_p",
  "id_orig_p",
  "id_orig_h",
  "conn_state",
  "id_resp_h",
  "id_resp_p",
  "service",
  "proto",
  "tags"
]
},
"sort": [
{
  "@timestamp": {
    "order": "desc"
  }
}
]
}

```

Now, I get the following error from this query.

```
 {
  "error" : {
  "root_cause" : [
  {
    "type" : "parsing_exception",
    "reason" : "[range] query does not support [runtime_timestamp]",
    "line" : 5,
    "col" : 9
  }
  ],
   "type" : "parsing_exception",
   "reason" : "[range] query does not support [runtime_timestamp]",
   "line" : 5,
   "col" : 9
  },
  "status" : 400
}

```

I tried this query also with `timestamp` in place of `runtime_timestamp`, and I still get the same error.

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [March 2, 2017, 11:43pm UTC](https://discuss.elastic.co/t/query-items-by-time-stamp-not-working/77229/2 "2017-03-02T23:43:41Z")

</div>

Your range query syntax is slightly off. You need to specify some kind of qualifier, like "gte" (greater than or equal to):

```auto
"range": {
  "runtime_timestamp": { 
    "gte" : "2017-03-02T21:56:53.033Z"
  }
}

```

Full syntax here: [https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html)

---

<div class="post-metadata">

**Author:** ![Ben\_Hoffman](https://avatars.discourse-cdn.com/v4/letter/b/71e660/32.png) [@Ben\_Hoffman](https://discuss.elastic.co/u/Ben_Hoffman)\
**Post date:** [March 3, 2017, 3:23pm UTC](https://discuss.elastic.co/t/query-items-by-time-stamp-not-working/77229/3 "2017-03-03T15:23:47Z")

</div>

That worked, thanks!

---

<div class="post-metadata">

**Author:** ![polyfractal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/polyfractal/32/48162_2.png) [@polyfractal](https://discuss.elastic.co/u/polyfractal)\
**Post date:** [March 3, 2017, 3:30pm UTC](https://discuss.elastic.co/t/query-items-by-time-stamp-not-working/77229/4 "2017-03-03T15:30:42Z")

</div>

Great! Happy to help 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2017, 3:30pm UTC](https://discuss.elastic.co/t/query-items-by-time-stamp-not-working/77229/5 "2017-03-31T15:30:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
