Best practices (5)
Limit searches by time (most recent or in a window)
More precise searches (similar to longest prefix)
Inclusion better than exclusion (and better than not)
Apply filtering
Use multiple indexes to segregate data
Time abbreviations
s: seconds
m: minutes
h: hours
d: days
w: weeks
mon: month
y: year
Time abbreviation @ symbol
rounds down to nearest time unit
-30m@h for 9:37 gives you 9:00-937
Time search strings (2)
Earliest
Latest
Most efficient way to filter events
By time