Retrieve more than 10 logs

(tomer zaks) #1


I wrote a query that asks for all messages ever sent, in a certain time range.
When looking at the data recieved there are only 10 logs in the output. How can I get all the logs from this time range.

index: 'filebeat-*',
                    type: 'log',
                       "query": {
                          "must": [
                                { "match": {"recordType":"MT"}},
                                  { "range": {
                                   "MedGotMsgFromApi": {
                                     "gte": gte,
                                     "lte": lte


(Mark Walkom) #2

Have a look at

(tomer zaks) #3


Now from looking in there, I saw:

Note that from + size can not be more than the index.max_result_window index setting which defaults to 10,000. See the Scroll or Search After API for more efficient ways to do deep scrolling.

does this mean I can't show more than 10,000 logs?

(Mark Walkom) #4

Not by default.

(system) #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.