I am trying to use elasticsearch filter but with no success.
I want to search logs to find past events and add fields to actual event.
I think this is due to 1 sec refresh of indices so when past events are
too close to actual event they are not available.
I tried to:
1.change ES output options in logstash
flush_size => 1
2.patched ES filter gem with action
client.indices.stats refresh: true
before search - but that's not working too!!
one working ugly solution - with
before search action
in ES filter
what am i doing/thinking wrong?
Is there another solution for searching past events in logstash?