# Retrieving all log events sorted by timestamp

**URL:** <https://discuss.elastic.co/t/retrieving-all-log-events-sorted-by-timestamp/173932>\
**Category:** Elasticsearch\
**Created:** [March 26, 2019, 12:55pm UTC](https://discuss.elastic.co/t/retrieving-all-log-events-sorted-by-timestamp/173932 "2019-03-26T12:55:54Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![oskargranlund](https://avatars.discourse-cdn.com/v4/letter/o/e47c2d/32.png) [@oskargranlund](https://discuss.elastic.co/u/oskargranlund)\
**Post date:** [March 26, 2019, 12:55pm UTC](https://discuss.elastic.co/t/retrieving-all-log-events-sorted-by-timestamp/173932/1 "2019-03-26T12:55:54Z")

</div>

I'm trying to retrieve all log events from an index by using python elasticsearch interface.

Currently I use this line of code in order to execute the query:  
scan(es, index="filebeat-2019.03.19", scroll="2m", query={"query": {"match": {"tags": "tag"}}})

It fetches data but the data is not sorted in chronological order according to the @timestamp field, is it possible to fetch the all available data sorted by timestamp?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 26, 2019, 1:10pm UTC](https://discuss.elastic.co/t/retrieving-all-log-events-sorted-by-timestamp/173932/2 "2019-03-26T13:10:33Z")

</div>

Yes. You can sort with [https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-sort.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-sort.html)

I believe you need to pass the `sort` part in the Python `query` parameter?

---

<div class="post-metadata">

**Author:** ![oskargranlund](https://avatars.discourse-cdn.com/v4/letter/o/e47c2d/32.png) [@oskargranlund](https://discuss.elastic.co/u/oskargranlund)\
**Post date:** [March 28, 2019, 10:28am UTC](https://discuss.elastic.co/t/retrieving-all-log-events-sorted-by-timestamp/173932/3 "2019-03-28T10:28:11Z")

</div>

I'm still struggeling with fetching sorted results. Do you mean something like this?  
query={ "sort": [{"source": {"timestamp": {"order": "asc"}}}], "query": { "match": {"tags": "tag"}} }  
Does this sort the result within each scroll or does it sort the entire search?  
I want to fetch about a million sorted log events.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [March 28, 2019, 12:06pm UTC](https://discuss.elastic.co/t/retrieving-all-log-events-sorted-by-timestamp/173932/4 "2019-03-28T12:06:03Z")

</div>

> [@oskargranlund](#):
>
> Do you mean something like this?

Yes.

> [@oskargranlund](#):
>
> Does this sort the result within each scroll or does it sort the entire search?

The entire search.

---

<div class="post-metadata">

**Author:** ![oskargranlund](https://avatars.discourse-cdn.com/v4/letter/o/e47c2d/32.png) [@oskargranlund](https://discuss.elastic.co/u/oskargranlund)\
**Post date:** [April 2, 2019, 8:23am UTC](https://discuss.elastic.co/t/retrieving-all-log-events-sorted-by-timestamp/173932/5 "2019-04-02T08:23:42Z")

</div>

Another question.. I am trying to use sort and query, however, they do not seem to work very well together. When having the sort line in the curl below everything is sorted correctly but the query is not applied to the results. When removing the sort line the result is not sorted but it is correctly filtered according to the query. What is going wrong? I've tried to move the position of the sort line to multiple positions with the same results.

res=$(curl -XGET --header 'Content-Type: application/json' host:port/index/\_search?scroll=5m -d '{  
"sort": [{"timestamp": {"order": "asc"}}],  
"query": {  
"bool" : {  
"must" : [  
{ "match" : {"tags" : "x, y"}},  
{ "match" : {"host.name" : "hostname"}}  
]  
}  
},  
"size": "10"  
}  
}')

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [April 2, 2019, 12:20pm UTC](https://discuss.elastic.co/t/retrieving-all-log-events-sorted-by-timestamp/173932/6 "2019-04-02T12:20:27Z")

</div>

That's another question. You should open a new discussion about it. And please provide a full recreation script as described in [About the Elasticsearch category](https://discuss.elastic.co/t/about-the-elasticsearch-category/21). It will help to better understand what you are doing. Please, try to keep the example as simple as possible.

A full reproduction script will help readers to understand, reproduce and if needed fix your problem. It will also most likely help to get a faster answer.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2019, 12:28pm UTC](https://discuss.elastic.co/t/retrieving-all-log-events-sorted-by-timestamp/173932/7 "2019-04-30T12:28:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
