# Setting hour in KQL or Lucene

**URL:** <https://discuss.elastic.co/t/setting-hour-in-kql-or-lucene/308740>\
**Category:** Kibana\
**Created:** [July 3, 2022, 9:23am UTC](https://discuss.elastic.co/t/setting-hour-in-kql-or-lucene/308740 "2022-07-03T09:23:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![hadi\_farzipour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hadi_farzipour/32/69187_2.png) [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Post date:** [July 3, 2022, 9:23am UTC](https://discuss.elastic.co/t/setting-hour-in-kql-or-lucene/308740/1 "2022-07-03T09:23:45Z")

</div>

Hello  
I have @timestamp field which is in following format

Jul 3, 2022 @ 06:55:55.153

How can I filter logs between 06:00 and 10:00 without mentioning days and months in KQL or Lucene query language.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [July 3, 2022, 10:10am UTC](https://discuss.elastic.co/t/setting-hour-in-kql-or-lucene/308740/2 "2022-07-03T10:10:20Z")

</div>

I suppose you need runtime field or some sripts.  
This video may help you.

[![](https://us1.discourse-cdn.com/elastic/original/3X/7/f/7f9de0ebb8b410dc90e9061604cd7da088211c11.jpeg "Creating a Day of Week Runtime Field and Using It in Kibana") ](https://www.youtube.com/watch?v=T4bZ35E6LgE)

---

<div class="post-metadata">

**Author:** ![hadi\_farzipour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hadi_farzipour/32/69187_2.png) [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Post date:** [July 4, 2022, 6:00am UTC](https://discuss.elastic.co/t/setting-hour-in-kql-or-lucene/308740/3 "2022-07-04T06:00:30Z")

</div>

Thanks, However I do not want to use mapping solution in my issue, because in 8.x and later version it is not able to use mapping.

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [July 4, 2022, 7:47am UTC](https://discuss.elastic.co/t/setting-hour-in-kql-or-lucene/308740/4 "2022-07-04T07:47:46Z")

</div>

Really? You can use [runtime mappings](https://www.elastic.co/guide/en/elasticsearch/reference/current/runtime-mapping-fields.html) also in 8.x.

---

<div class="post-metadata">

**Author:** ![hadi\_farzipour](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hadi_farzipour/32/69187_2.png) [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Post date:** [July 5, 2022, 5:02am UTC](https://discuss.elastic.co/t/setting-hour-in-kql-or-lucene/308740/5 "2022-07-05T05:02:59Z")

</div>

Thanks Tomo for your replies  
I have resolved my problem by creating an scripted fields which contain following script.

return LocalDateTime.ofInstant(Instant.ofEpochMilli(doc['@timestamp'].value.millis),ZoneId.of('Iran')).getHour()

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 2, 2022, 5:03am UTC](https://discuss.elastic.co/t/setting-hour-in-kql-or-lucene/308740/6 "2022-08-02T05:03:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
