Elasticsearch query sort order index



if - in a Elasticsearch filter plugin - I do the following:

elasticsearch {
	hosts => ["elasticsearch:9200"]
	index => ["logstash-*"]

And let's assume I have several Logstash indexes like e.g.


Where is the query supposed to search? Only in the latest? Only in the oldest? In all of them?

(Magnus Bäck) #2

It'll search all indexes that match the index name pattern you've given.


Thank you.

Providing in the elasticsearch filter plugin these settings:

result_size => 1
enable_sort => true

Do you think Logstash will return only the first match found in index logstash-2018.06.24 or something else?

(Magnus Bäck) #4

Assuming the timestamp is the sort key I'd expect it to return the first document in the first index.

(system) #5

