# "query" that combines range and term in ElasticSearch plugin in Logstash input

**URL:** https://discuss.elastic.co/t/query-that-combines-range-and-term-in-elasticsearch-plugin-in-logstash-input/151057
**Category:** Logstash
**Created:** [October 4, 2018, 2:13pm UTC](https://discuss.elastic.co/t/query-that-combines-range-and-term-in-elasticsearch-plugin-in-logstash-input/151057 "2018-10-04T14:13:55Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Dolph\_2709](https://avatars.discourse-cdn.com/v4/letter/d/258eb7/32.png) [@Dolph\_2709](https://discuss.elastic.co/u/Dolph_2709)
#### Post date: [October 4, 2018, 2:13pm UTC](https://discuss.elastic.co/t/query-that-combines-range-and-term-in-elasticsearch-plugin-in-logstash-input/151057/1 "2018-10-04T14:13:56Z")

</div>

Hello,

I need a help with "query" syntax in Elasticsearch plugin.  
Currently my input looks like this (and it works OK):

> input {  
> elasticsearch {  
> hosts =\> ["1x.1x.1xx.1xx:9200"]  
> index =\> "worklight"  
> scroll =\> "10m"  
> size =\> 4000  
> query =\> '{ "query": { "range": { "timestamp": {"gt":"now-10m/m", "lte" :"now" } } } }'  
> docinfo =\> true  
> schedule =\> "\* \* \* \* \*"  
> }  
> }

I need to introduce an extra filtering in the query by the log type. Could you, please, help me with query syntax?  
Is this right?

> query =\> '{ "query": { "query\_string": {"query": "type: MfpAppLogs"} AND "range": { "timestamp": {"gte":"now-365s", "lte" :"now-300s" } } } }'

or this?

> query =\> '{ "query": { "query\_string": {"query": "type: MfpAppLogs"}, "range": { "timestamp": {"gte":"now-365s", "lte" :"now-300s" } } } }'

Thank you!

---

<div class="post-metadata">

### Author: ![Dolph\_2709](https://avatars.discourse-cdn.com/v4/letter/d/258eb7/32.png) [@Dolph\_2709](https://discuss.elastic.co/u/Dolph_2709)
#### Post date: [October 4, 2018, 7:55pm UTC](https://discuss.elastic.co/t/query-that-combines-range-and-term-in-elasticsearch-plugin-in-logstash-input/151057/2 "2018-10-04T19:55:45Z")

</div>

I guess I found the answer, it was a tricky change:

> query =\> '{ "query": { "bool": { "must": [{ "term": { "\_type": "MfpAppLogs" }}, { "range": { "timestamp": {"gte":"now-365s", "lte" :"now-300s" } } }] } } }'

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [November 1, 2018, 7:55pm UTC](https://discuss.elastic.co/t/query-that-combines-range-and-term-in-elasticsearch-plugin-in-logstash-input/151057/3 "2018-11-01T19:55:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
