# Querying documents for the past 10 minutes is not working

**URL:** <https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288>\
**Category:** Elasticsearch\
**Created:** [October 10, 2017, 4:04am UTC](https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288 "2017-10-10T04:04:35Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![cocoonryan](https://avatars.discourse-cdn.com/v4/letter/c/919ad9/32.png) [@cocoonryan](https://discuss.elastic.co/u/cocoonryan)\
**Post date:** [October 10, 2017, 4:04am UTC](https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288/1 "2017-10-10T04:04:35Z")

</div>

i have a query like this to query documents within the past 10 minutes, but it returns documents outside the 10 minutes range.  
{  
"\_source": ["timestamp"],  
"query": {  
"range":{  
"timestamp":{  
"gt": "now-10m"  
}  
}  
}  
}

This is a sample of my timestamp format:  
"timestamp": "2017-10-10T09:59:26.601417"

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 10, 2017, 5:58am UTC](https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288/2 "2017-10-10T05:58:48Z")

</div>

Just to make sure: timestamp is a date field in the mapping, right? Any chance it’s a text instead?

What was the server time when you ran the query? Note that elasticsearch assumes by default UTC time.

---

<div class="post-metadata">

**Author:** ![cocoonryan](https://avatars.discourse-cdn.com/v4/letter/c/919ad9/32.png) [@cocoonryan](https://discuss.elastic.co/u/cocoonryan)\
**Post date:** [October 10, 2017, 7:36am UTC](https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288/3 "2017-10-10T07:36:08Z")

</div>

I checked my mappings and it shows that the date is in date type.

```auto
"timestamp": {
 "type": "date"
},

```

I changed the format of my timestamp from my django app.

```auto
['timestamp'] = datetime.now().isoformat()[:-3] + 'Z'

```

which give the result of

```auto
"timestamp": "2017-10-10T09:59:26.601Z"

```

I tried again the range query but it returns the same issue.

---

<div class="post-metadata">

**Author:** ![Azharuddin](https://avatars.discourse-cdn.com/v4/letter/a/71e660/32.png) [@Azharuddin](https://discuss.elastic.co/u/Azharuddin)\
**Post date:** [October 10, 2017, 7:39am UTC](https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288/4 "2017-10-10T07:39:22Z")

</div>

Thanks for the information.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 10, 2017, 8:19am UTC](https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288/5 "2017-10-10T08:19:19Z")

</div>

What was the server time when you ran the query?

---

<div class="post-metadata">

**Author:** ![cocoonryan](https://avatars.discourse-cdn.com/v4/letter/c/919ad9/32.png) [@cocoonryan](https://discuss.elastic.co/u/cocoonryan)\
**Post date:** [October 10, 2017, 8:44am UTC](https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288/6 "2017-10-10T08:44:52Z")

</div>

I run a query with a timestamp of  
"timestamp": "2017-10-10T16:38:14.296Z"  
but i still get the other documents that shouldnt be there.

and i checked the server time, and it is in UTC which is the same with ES.

I tried to add format in my query, but still no success.

```auto
{
	"_source": ["timestamp"],
	"query" : { 
        "range" : {
        	"timestamp":{
        		"gt": "now-5m",
        		"format": "strict_date_time||yyyy-MM-dd'T'HH:mm:ss.SSSZ"
        	}
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![cocoonryan](https://avatars.discourse-cdn.com/v4/letter/c/919ad9/32.png) [@cocoonryan](https://discuss.elastic.co/u/cocoonryan)\
**Post date:** [October 10, 2017, 9:34am UTC](https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288/7 "2017-10-10T09:34:24Z")

</div>

just an update. I tried to run the query via curl in my local computer and in our server to validated both date and time.  
both curl request had the same result..

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [October 10, 2017, 9:51am UTC](https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288/8 "2017-10-10T09:51:28Z")

</div>

I ran that on my laptop at 11:49 (I'm GMT+2 TZ):

```auto
DELETE dpi
PUT dpi
{
  "mappings": {
    "doc": {
      "properties": {
        "timestamp": {
          "type": "date"
        }
      }
    }
  }
}
PUT dpi/doc/1
{
  "timestamp": "2017-10-10T11:45:00+02:00"
}
PUT dpi/doc/2
{
  "timestamp": "2017-10-10T11:30:00+02:00"
}
POST dpi/_refresh
GET dpi/_search
{
  "query": {
    "range": {
      "timestamp": {
        "gt": "now-5m"
      }
    }
  }
}

```

It gave me the right results:

```auto
{
  "took": 0,
  "timed_out": false,
  "_shards": {
    "total": 5,
    "successful": 5,
    "skipped": 0,
    "failed": 0
  },
  "hits": {
    "total": 1,
    "max_score": 1,
    "hits": [
      {
        "_index": "dpi",
        "_type": "doc",
        "_id": "1",
        "_score": 1,
        "_source": {
          "timestamp": "2017-10-10T11:45:00+02:00"
        }
      }
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![cocoonryan](https://avatars.discourse-cdn.com/v4/letter/c/919ad9/32.png) [@cocoonryan](https://discuss.elastic.co/u/cocoonryan)\
**Post date:** [October 10, 2017, 11:01am UTC](https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288/9 "2017-10-10T11:01:34Z")

</div>

Hi @dadoonet.

its working on my end now. So here's what we did, for other people's reference.

I set my timestamp(local timezone) in my django app:  
timestamp = datetime.now(pytz.timezone("Asia/Manila")).isoformat()

which results with this timestamp in my elasticsearch document:  
"timestamp": "2017-10-10T18:34:21.786623+08:00"

I also change this query

{  
"\_source": ["timestamp"],  
"query": {  
"range": {  
"timestamp": {  
"gte": "now-10m"  
}  
}  
},  
"sort": {"timestamp": {"order": "desc"}}  
}

with this one:

{  
"\_source": ["timestamp"],  
"query": {  
"range": {  
"timestamp": {  
"gte": "now-10m/m",  
"lte": "now/m"  
}  
}  
},  
"sort": {"timestamp": {"order": "desc"}}  
}

and it works. I understand now how date format affects my query but it keeps me wondering why I need to add the rounding up option and "lte": "now/m" in my query?

---

<div class="post-metadata">

**Author:** ![cocoonryan](https://avatars.discourse-cdn.com/v4/letter/c/919ad9/32.png) [@cocoonryan](https://discuss.elastic.co/u/cocoonryan)\
**Post date:** [October 10, 2017, 11:05am UTC](https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288/10 "2017-10-10T11:05:04Z")

</div>

Thank you @dadoonet! 👍

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 7, 2017, 11:05am UTC](https://discuss.elastic.co/t/querying-documents-for-the-past-10-minutes-is-not-working/103288/11 "2017-11-07T11:05:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
