# Search API limiting output

**URL:** <https://discuss.elastic.co/t/search-api-limiting-output/187301>\
**Category:** Elasticsearch\
**Created:** [June 25, 2019, 10:13am UTC](https://discuss.elastic.co/t/search-api-limiting-output/187301 "2019-06-25T10:13:57Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [June 25, 2019, 10:13am UTC](https://discuss.elastic.co/t/search-api-limiting-output/187301/1 "2019-06-25T10:13:58Z")

</div>

How do I use the search API to query over a period of time? (last 15mins) and also to limit the output to a size of 1.

I have the below working, but that searches for everything up to 10,000 docs.

`POST index/_search?q=host:FW1`

---

<div class="post-metadata">

**Author:** ![sjabiulla](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/sjabiulla/32/48429_2.png) [@sjabiulla](https://discuss.elastic.co/u/sjabiulla)\
**Post date:** [June 25, 2019, 10:33am UTC](https://discuss.elastic.co/t/search-api-limiting-output/187301/2 "2019-06-25T10:33:06Z")

</div>

Refer [this](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html) to query over a period of time

Refer [this](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-request-from-size.html) to limit the output size to 1

---

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [June 25, 2019, 10:34am UTC](https://discuss.elastic.co/t/search-api-limiting-output/187301/3 "2019-06-25T10:34:14Z")

</div>

Is it not possible to pass it all in one request? Rather than adding the json?

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 25, 2019, 10:35am UTC](https://discuss.elastic.co/t/search-api-limiting-output/187301/4 "2019-06-25T10:35:55Z")

</div>

> [@Jasonespo](#):
>
> I have the below working, but that searches for everything up to 10,000 docs.

It's actually searching for more than that. If you have 1m documents matching all of them are "searched". The number of hits you have in the response basically tells you that we found at least 10000 documents matching.  
You can have the exact number but this optional.

Setting `size: 1` will just return the first top document (sorted by `_score`) but it will still search for everything.

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 25, 2019, 10:37am UTC](https://discuss.elastic.co/t/search-api-limiting-output/187301/5 "2019-06-25T10:37:12Z")

</div>

Yes. I don't like it but you can: [https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#\_ranges](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-query-string-query.html#_ranges)

---

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [June 25, 2019, 10:42am UTC](https://discuss.elastic.co/t/search-api-limiting-output/187301/6 "2019-06-25T10:42:39Z")

</div>

Perfect thank you.

Last question - When we set the size to one, is it possible to limit the response output so that we don't get the hits array returned? Only that there is a total of "1" hit.

---

<div class="post-metadata">

**Author:** ![Jasonespo](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@Jasonespo](https://discuss.elastic.co/u/Jasonespo)\
**Post date:** [June 25, 2019, 11:03am UTC](https://discuss.elastic.co/t/search-api-limiting-output/187301/7 "2019-06-25T11:03:16Z")

</div>

The range doesn't seem to affect the amount of "hits" that are brought back.

Even when setting it to now-1s it still says there are 10,000. Is that because you mentioned it searches everything regardless of the size? Can it not search only for the last 5minutes, like we can using the discover tool and KQL? This is because do not want the request to take any noticeable period of time once there are more logs stored in ES.

```
POST index/_search?q=host:FW1
{
    "size": 1,
    "query": {
       "range": {
                    "timestamp": {
                      "gte": "now-1s"
                }
          }
     }
}
```

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 25, 2019, 11:22am UTC](https://discuss.elastic.co/t/search-api-limiting-output/187301/8 "2019-06-25T11:22:10Z")

</div>

you can't use both URI syntax and body.

So you should use a `bool` query with a `filter` array containing your `range` query and probably a `match` query on field `host` with value `FW1`.

Again `size` only tells you how many documents you want to return back within the response. Like the `size` of the page. 10 documents per "page" is the default value.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2019, 11:22am UTC](https://discuss.elastic.co/t/search-api-limiting-output/187301/9 "2019-07-23T11:22:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
