summary: I am trying to find a way to have many "objects", and query their properties in certain time points.
I'm having a problem implementing ELK and I need some advice.
I have a database that a part of it is defects that are documented, and am using logstash and JDBC to withdraw these defects to elasticsearch, they are constantly changing and being updated(opened, closed, reopened etc).
So far all is good, I can schedule logstash to run every day and only withdraw the update so I get in my database many documents of defects, some of the have the same ID, properties of that defect and the time it was modified. But now I need to go back and query the state of all defects in a certain time (how many opened, how many closed etc). I can't seem to find a good way to do it, since a document is a point in time rather than a property of a certain object.
I realy need an advice how to map/arrange/filter my data in such a way this will be possible.
Hopefully I made myself clear enough.
thank you very much,