# Want to extract data for last 15 days only for business hour by skipping other than business hours

**URL:** <https://discuss.elastic.co/t/want-to-extract-data-for-last-15-days-only-for-business-hour-by-skipping-other-than-business-hours/353972>\
**Category:** Elastic Search\
**Tags:** elastic-app-search\
**Created:** [February 23, 2024, 10:32am UTC](https://discuss.elastic.co/t/want-to-extract-data-for-last-15-days-only-for-business-hour-by-skipping-other-than-business-hours/353972 "2024-02-23T10:32:51Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![2328943\_dc](https://avatars.discourse-cdn.com/v4/letter/2/a9adbd/32.png) [@2328943\_dc](https://discuss.elastic.co/u/2328943_dc)\
**Post date:** [February 23, 2024, 10:32am UTC](https://discuss.elastic.co/t/want-to-extract-data-for-last-15-days-only-for-business-hour-by-skipping-other-than-business-hours/353972/1 "2024-02-23T10:32:51Z")

</div>

We want to extract data for last 15 days only for business hour[8AM-8PM]  
by skipping other than business hours .  
Is it possible to extract data like this in one file download only ?

---

<div class="post-metadata">

**Author:** ![Kathleen\_DeRusso](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kathleen_derusso/32/132039_2.png) [@Kathleen\_DeRusso](https://discuss.elastic.co/u/Kathleen_DeRusso)\
**Post date:** [February 23, 2024, 1:13pm UTC](https://discuss.elastic.co/t/want-to-extract-data-for-last-15-days-only-for-business-hour-by-skipping-other-than-business-hours/353972/2 "2024-02-23T13:13:51Z")

</div>

By "extract data" I assume you mean query it from an existing index? It all depends on what you have indexed, and different ways of organizing your indexing schema can make this easier or harder. For example if you enrich your logs with a field to indicate that this is within your core business hours, it becomes a very simple query.

You can formulate queries to filter based on date ranges. You'll want to look at the [range](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-range-query.html) query, and depending on your schema may need to do a [boolean](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-dsl-bool-query.html) query.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 1, 2024, 10:05am UTC](https://discuss.elastic.co/t/want-to-extract-data-for-last-15-days-only-for-business-hour-by-skipping-other-than-business-hours/353972/4 "2024-03-01T10:05:45Z")

</div>

@2328943_dc take a look at this...

> [@Extracting time from @timestamp field using Runtime](https://discuss.elastic.co/t/extracting-time-from-timestamp-field-using-runtime/348468/4):
>
> So you need to look at examples here... And the API Here... [java.time](https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-api-reference-shared-java-time.html)[java.time.chrono](https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-api-reference-shared-java-time-chrono.html)[java.time.format](https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-api-reference-shared-java-time-format.html)[java.time.temporal](https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-api-reference-shared-java-time-temporal.html)[java.time.zone](https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-api-reference-shared-java-time-zone.html) OK we can do that as a keyword... filtering and sorting you will need to see if that works... You will need to figure out the timezone stuff if you want to... ZonedDateTime zdt = doc['@timestamp'].value; String datetime = zdt.format(DateTimeFormatter.ISO\_LOCAL\_TIME); emit(datetime);

I think it will help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 29, 2024, 10:05am UTC](https://discuss.elastic.co/t/want-to-extract-data-for-last-15-days-only-for-business-hour-by-skipping-other-than-business-hours/353972/5 "2024-03-29T10:05:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
