# Relative searches with API

**URL:** <https://community.graylog.org/t/relative-searches-with-api/26022>\
**Category:** Development\
**Tags:** elastic\
**Created:** [October 4, 2022, 12:01pm UTC](https://community.graylog.org/t/relative-searches-with-api/26022 "2022-10-04T12:01:14Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![weird-oecophylla](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/weird-oecophylla/32/11147_2.png) [@weird-oecophylla](https://community.graylog.org/u/weird-oecophylla)\
**Post date:** [October 4, 2022, 12:01pm UTC](https://community.graylog.org/t/relative-searches-with-api/26022/1 "2022-10-04T12:01:14Z")

</div>

Hi,

I’m trying to retrieve a lot of logs from Graylog using an automated script in javascript.

Because of the huge ammount of logs, I need to make many requests with different offset as Graylog returns are limited.

Currently I am testing the script by requesting 1000 logs by 1000 logs

```auto
> /api/search/universal/relative

with
range: 0
decorate:false
limit:1000
offset:0

```

After each request I set **offset = offset + limit.**

This works well until the offset is **10.000**. Once offset=10000 → I get an error 500:

> {“type”:“ApiError”,“message”:“Unable to perform search query”}

I read the error was caused by the **max\_result\_window** from elasticsearch which is by default set to 10.000.

**However** , I don’t understand why this limit impacts me because my searches results are limited to 1000 logs for each request !

I mean requesting the logs between 10.000 and 11.000 should return 1000 logs anyway so why would I be concerned the **max\_result\_window limit**?

Does it comes from the way is working the endpoint: **/api/search/universal/relative**?

If the only solution is to increase the max\_result\_window limit, what coudl be the consequences in terms of resources consuming ? This remediation would be also limited because increasing the limit to 50.000 would not allow me to request the 1000 logs between 50.000 and 51.000.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [October 4, 2022, 9:18pm UTC](https://community.graylog.org/t/relative-searches-with-api/26022/2 "2022-10-04T21:18:07Z")

</div>

Hello @weird-oecophylla

I did a test from the info you gave\ through GL’s API. I did not receive an error 500.

Example:

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/b/b80cdb82ec135c40722001aa1c765e2c3bb5ccaf.png)

AND with limit.

 ![image](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/2X/2/2eb614e4febe55709b248e1eebf12a851e352572.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [October 18, 2022, 9:18pm UTC](https://community.graylog.org/t/relative-searches-with-api/26022/3 "2022-10-18T21:18:23Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
