# @timestamp range - searching across indices

**URL:** <https://discuss.elastic.co/t/timestamp-range-searching-across-indices/52290>\
**Category:** Elasticsearch\
**Created:** [June 9, 2016, 7:08am UTC](https://discuss.elastic.co/t/timestamp-range-searching-across-indices/52290 "2016-06-09T07:08:01Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![stesey19](https://avatars.discourse-cdn.com/v4/letter/s/a698b9/32.png) [@stesey19](https://discuss.elastic.co/u/stesey19)\
**Post date:** [June 9, 2016, 7:08am UTC](https://discuss.elastic.co/t/timestamp-range-searching-across-indices/52290/1 "2016-06-09T07:08:01Z")

</div>

Hi all,

I am new to Elasticsearch and would like to know if it's possible to retrieve all logs over the last 24 hours while searching across all indices?

I am running the below queries using Sense. When I run the first query it selects data as expected but when I run the second query it selects dates from days ago

Query:  
GET /logstash-sdnet-2016.06.08,logstash-sdnet-2016.06.09/\_search  
{  
"filter":{  
"range":{"@timestamp":{"gte":"now-24h"}}}  
}

Results:  
{  
"took": 2,  
"timed\_out": false,  
"\_shards": {  
"total": 10,  
"successful": 10,  
"failed": 0  
},  
"hits": {  
"total": 19431,  
"max\_score": 1,  
"hits": [  
{  
"\_index": "logstash-sdnet-2016.06.08",  
"\_type": "collectd",  
"\_id": "AVTcO26tvGUlWg6s43sU",  
"\_score": 1,  
"\_source": {  
"host": "[ups.l.dwyer.id.au](http://ups.l.dwyer.id.au)",  
"@timestamp": "2016-06-08T08:06:45.000Z",  
"plugin": "UPS",  
"value": 0,  
"type": "collectd",  
"metric": "apc\_smartups\_BattTimeOn",  
"customer": "SDNet"  
}  
},  
{  
"\_index": "logstash-sdnet-2016.06.08",  
"\_type": "collectd",  
"\_id": "AVTcO26tvGUlWg6s43sa",  
"\_score": 1,  
"\_source": {  
"host": "[ups.l.dwyer.id.au](http://ups.l.dwyer.id.au)",  
"@timestamp": "2016-06-08T08:06:45.000Z",  
"plugin": "UPS",  
"value": 247.6,  
"type": "collectd",  
"metric": "apc\_smartups\_OutputV",  
"customer": "SDNet"  
}  
},

Query:  
GET /logstash-sdnet-\*/\_search  
{  
"filter":{  
"range" : {  
"@timestamp" : {  
"gt" : "now-24h"}}}  
}

Results:  
{  
"took": 54,  
"timed\_out": false,  
"\_shards": {  
"total": 650,  
"successful": 650,  
"failed": 0  
},  
"hits": {  
"total": 173882,  
"max\_score": 1,  
"hits": [  
{  
"\_index": "logstash-sdnet-2016.05.23",  
"\_type": "collectd",  
"\_id": "AVS0qT1MvGUlWg6s4R-C",  
"\_score": 1,  
"\_source": {  
"host": "[ups.l.dwyer.id.au](http://ups.l.dwyer.id.au)",  
"@timestamp": "2016-05-23T05:16:45.000Z",  
"plugin": "UPS",  
"value": 100,  
"type": "collectd",  
"metric": "apc\_smartups\_BattCapacity",  
"customer": "SDNet"  
}  
},  
{  
"\_index": "logstash-sdnet-2016.05.23",  
"\_type": "collectd",  
"\_id": "AVS0qT1MvGUlWg6s4R-E",  
"\_score": 1,  
"\_source": {  
"host": "[ups.l.dwyer.id.au](http://ups.l.dwyer.id.au)",  
"@timestamp": "2016-05-23T05:16:45.000Z",  
"plugin": "UPS",  
"value": 246.2,  
"type": "collectd",  
"metric": "apc\_smartups\_InputVmax",  
"customer": "SDNet"  
}  
},

Mapping:  
"@timestamp": {  
"type": "date",  
"format": "strict\_date\_optional\_time||epoch\_millis"  
},

Do you always need to specify the index when searching for date ranges?

Many thanks!

---

<div class="post-metadata">

**Author:** ![mikemccand](https://avatars.discourse-cdn.com/v4/letter/m/f04885/32.png) [@mikemccand](https://discuss.elastic.co/u/mikemccand)\
**Post date:** [June 9, 2016, 1:04pm UTC](https://discuss.elastic.co/t/timestamp-range-searching-across-indices/52290/2 "2016-06-09T13:04:41Z")

</div>

No, the second query should also have worked (only returned hits in the past day).

The query looks correct to me, but to be sure, can you try specifying some older index names (that have no hits within the past day) and confirm you get 0 hits?

Mike McCandless

---

<div class="post-metadata">

**Author:** ![stesey19](https://avatars.discourse-cdn.com/v4/letter/s/a698b9/32.png) [@stesey19](https://discuss.elastic.co/u/stesey19)\
**Post date:** [June 9, 2016, 2:13pm UTC](https://discuss.elastic.co/t/timestamp-range-searching-across-indices/52290/3 "2016-06-09T14:13:59Z")

</div>

Hi there,

If I run the below query for 2016.05.25 and 2016.05.26 I get hits

GET /logstash-sdnet-2016.05.25,logstash-sdnet-2016.05.26/\_search  
{  
"filter":{  
"range":{"@timestamp":{"gte":"now-24h"}}}  
}

{  
"took": 2,  
"timed\_out": false,  
"\_shards": {  
"total": 10,  
"successful": 10,  
"failed": 0  
},  
"hits": {  
"total": 31437,  
"max\_score": 1,  
"hits": [  
{  
"\_index": "logstash-sdnet-2016.05.25",  
"\_type": "collectd",  
"\_id": "AVS8EgH2vGUlWg6s4ZCA",  
"\_score": 1,  
"\_source": {  
"host": "[ups.l.dwyer.id.au](http://ups.l.dwyer.id.au)",  
"@timestamp": "2016-05-25T02:36:45.000Z",  
"plugin": "UPS",  
"value": 0,  
"type": "collectd",  
"metric": "apc\_smartups\_BattTimeOn",  
"customer": "SDNet"  
}  
},  
{  
"\_index": "logstash-sdnet-2016.05.25",  
"\_type": "collectd",  
"\_id": "AVS8EgH2vGUlWg6s4ZCF",  
"\_score": 1,  
"\_source": {  
"host": "[ups.l.dwyer.id.au](http://ups.l.dwyer.id.au)",  
"@timestamp": "2016-05-25T02:36:45.000Z",  
"plugin": "UPS",  
"value": 50,  
"type": "collectd",  
"metric": "apc\_smartups\_InputFreq",  
"customer": "SDNet"  
}  
},

☹

---

<div class="post-metadata">

**Author:** ![mikemccand](https://avatars.discourse-cdn.com/v4/letter/m/f04885/32.png) [@mikemccand](https://discuss.elastic.co/u/mikemccand)\
**Post date:** [June 9, 2016, 11:29pm UTC](https://discuss.elastic.co/t/timestamp-range-searching-across-indices/52290/4 "2016-06-09T23:29:52Z")

</div>

Hmm, maybe try the explain API?

[https://www.elastic.co/guide/en/elasticsearch/reference/current/search-explain.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-explain.html)

---

<div class="post-metadata">

**Author:** ![stesey19](https://avatars.discourse-cdn.com/v4/letter/s/a698b9/32.png) [@stesey19](https://discuss.elastic.co/u/stesey19)\
**Post date:** [June 10, 2016, 9:54am UTC](https://discuss.elastic.co/t/timestamp-range-searching-across-indices/52290/5 "2016-06-10T09:54:38Z")

</div>

Thank you!

I'll give this a try and see what I find

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 10:44pm UTC](https://discuss.elastic.co/t/timestamp-range-searching-across-indices/52290/6 "2017-07-05T22:44:49Z")

</div>


