This looks like a field name that represents a timestamp in nanoseconds. If this is the case it is very bad and will result in mapping explosion. If this is indeed the case I would recommend you change how you index data.
That is still likely to grow almost linearly over time so is still very bad. You will hit system limits and if you just increase these as a workaround the cluster will eventually grind to a halt. It would be better to move it into a field, e.g. "tweet_id": "1655160784605913090". I suspect this would also solve your query problem as you would then know the full path of the field to query.