# Timestamp search between two fields

**URL:** <https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048>\
**Category:** Elasticsearch\
**Created:** [March 31, 2023, 12:54pm UTC](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048 "2023-03-31T12:54:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Farah\_Bhr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farah_bhr/32/82537_2.png) [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Post date:** [March 31, 2023, 12:54pm UTC](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048/1 "2023-03-31T12:54:02Z")

</div>

In my use case, I created two fields for the values of start\_time and end\_time based on some indicators in the log lines  
with kibana discover , I want to search for all the log lines that their timestamp is between these two fields start\_time and end\_time  
any ideas please?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 1, 2023, 3:30pm UTC](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048/2 "2023-04-01T15:30:10Z")

</div>

Hi @Farah_Bhr

It would look something like this but with your field names

`@timestamp >= "2023-03-28T16:31:07.611Z" and event.ingested <= "2023-03-29T16:31:07.611Z" `

 ![Screenshot 2023-04-01 at 8.31.59 AM](https://us1.discourse-cdn.com/elastic/original/3X/a/0/a00899947031475de9415848d2b7a4368dc7eaef.png)

---

<div class="post-metadata">

**Author:** ![Farah\_Bhr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farah_bhr/32/82537_2.png) [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Post date:** [April 2, 2023, 12:56am UTC](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048/3 "2023-04-02T00:56:51Z")

</div>

Hello , thank you for your response  
I didn't understand exactly your use case  
In fact I know there is such an option with \>= and \< , but I want to search for the @timestamp between two already defined fields , meaning , instead of searching with timestamp values like this :

```auto
{
          "range": {
            "@timestamp": {
              "gte": "2023-03-03T15:00:00.000Z",
              "lte": "2023-03-03T17:00:00.000Z"
            }
          }
        }

```

I want to change it to something similar to this (or using dynamic variables):

```auto
{
          "range": {
            "@timestamp": {
              "gte": "start_time",
              "lte": "end_time"
            }
          }
        }

```

With start\_time and end\_time are fields I defined so that "gte" and "lte" take the values of start\_time and end\_time fields  
I don't know if there is a way to do so ?  
If you can help me with this  
Thank you in advance

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 2, 2023, 2:15am UTC](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048/4 "2023-04-02T02:15:26Z")

</div>

Kibana Discover KQL or filters do not operate on the value within another field, they operate on discreet values.

Where / How were you thinking you would define the start and end time values?.. in a Document?

---

<div class="post-metadata">

**Author:** ![Farah\_Bhr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farah_bhr/32/82537_2.png) [@Farah\_Bhr](https://discuss.elastic.co/u/Farah_Bhr)\
**Post date:** [April 2, 2023, 11:32am UTC](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048/5 "2023-04-02T11:32:53Z")

</div>

Ah okay , so this is not possible

I thought of it because in my use case , I have a lot of logs and I want to search in the log lines for an id and its flow (all logs lines related to that id) in the logs , and for every id I have indicators in the message log lines knowing that this specific id started and finished.  
For example, when I have this message in the log lines "Created new id 0x56789" , I know that the flow of this specific id started , so that's why I thought of creating with logstash a new field to detect the start\_time and end\_time

If you have any ideas or if you can help me with this ?  
Thank you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 30, 2023, 11:33am UTC](https://discuss.elastic.co/t/timestamp-search-between-two-fields/329048/6 "2023-04-30T11:33:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
