# View Data from specific index over 24hr period

**URL:** <https://discuss.elastic.co/t/view-data-from-specific-index-over-24hr-period/288941>\
**Category:** Kibana\
**Created:** [November 11, 2021, 2:06am UTC](https://discuss.elastic.co/t/view-data-from-specific-index-over-24hr-period/288941 "2021-11-11T02:06:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wilks](https://avatars.discourse-cdn.com/v4/letter/w/f475e1/32.png) [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Post date:** [November 11, 2021, 2:06am UTC](https://discuss.elastic.co/t/view-data-from-specific-index-over-24hr-period/288941/1 "2021-11-11T02:06:14Z")

</div>

Hi,  
I am trying to come up with a way to view the data from a field within Elasticsearch index called "dns.highest\_registered\_domain" over a 24 hour period. I have come up with the following but I am not sure if it is over 24hrs, also is there a way to just display the data in the "dns.highest\_registered\_domain field"? without getting getting all the other fields

```auto
GET /index-*/_search
{
    "query": {
        "exists": {
            "field": "dns.highest_registered_domain"
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 11, 2021, 2:22am UTC](https://discuss.elastic.co/t/view-data-from-specific-index-over-24hr-period/288941/2 "2021-11-11T02:22:10Z")

</div>

First I would probably use the Discover App in Kibana get a sense.

But query could look like this.

To just get the fields want [here](https://www.elastic.co/guide/en/elasticsearch/reference/7.15/search-fields.html)

You need to include a range filter.

Perhaps take a look [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html#ranges-on-dates).

You also want to understand Query + Filter Context [here](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-filter-context.html#query-filter-context-ex)

```auto
GET /indext-*/_search
{
  "fields": [
    "dns.highest_registered_domain"
  ],
  "query": {
    "bool": {
      "must": {
        "exists": {
          "field": "dns.highest_registered_domain"
        }
      },
      "filter": {
        "range": {
          "@timestamp": {
            "gte": "now-24h/h"
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Wilks](https://avatars.discourse-cdn.com/v4/letter/w/f475e1/32.png) [@Wilks](https://discuss.elastic.co/u/Wilks)\
**Post date:** [November 11, 2021, 2:11pm UTC](https://discuss.elastic.co/t/view-data-from-specific-index-over-24hr-period/288941/3 "2021-11-11T14:11:15Z")

</div>

> [@stephenb](#):
>
> ```auto
> {
> "fields" : ["dns.highest_registered_domain"],
> "query": {
> "exists": {
> "field": "dns.highest_registered_domain"
> }
> },
> "filter": [ 
> { "range": { "@timestamp": { "gte": "now-24h/h" }}}
> ]
> }
> 
> ```

Thanks. This works if I remove everything below the "filter": statement. If I leave it in I get, I just cant figure out how to structure the "filter': statement to get it to pull over 24hrs

```auto
{
  "error" : {
    "root_cause" : [
      {
        "type" : "parsing_exception",
        "reason" : "Unknown key for a START_ARRAY in [filter].",
        "line" : 8,
        "col" : 15
      }
    ],
    "type" : "parsing_exception",
    "reason" : "Unknown key for a START_ARRAY in [filter].",
    "line" : 8,
    "col" : 15
  },
  "status" : 400
}

```

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [November 11, 2021, 2:48pm UTC](https://discuss.elastic.co/t/view-data-from-specific-index-over-24hr-period/288941/4 "2021-11-11T14:48:51Z")

</div>

@Wilks

Apologies... I am not sure _ **what** _ I pasted in above.. I fixed it... so that someone looking does not have the same experience as you.. Sorry again for that.

Here is the correct syntax...

This is based on the concept of Query + Filter Context its needs a bool, and both the Query and Filter _can_ be arrays but in this case a single element can work.

> **[Query and filter context | Elasticsearch Guide \[7.15\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-filter-context.html#query-filter-context-ex)**

```auto
GET /index-*/_search
{
  "fields": [
    "dns.highest_registered_domain"
  ],
  "query": {
    "bool": {
      "must": {
        "exists": {
          "field": "dns.highest_registered_domain"
        }
      },
      "filter": {
        "range": {
          "@timestamp": {
            "gte": "now-24h/h"
          }
        }
      }
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 9, 2021, 2:49pm UTC](https://discuss.elastic.co/t/view-data-from-specific-index-over-24hr-period/288941/5 "2021-12-09T14:49:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
