Elasticsearch query sort order index

Hi,

if - in a Elasticsearch filter plugin - I do the following:

elasticsearch {
	hosts => ["elasticsearch:9200"]
	index => ["logstash-*"]
...

And let's assume I have several Logstash indexes like e.g.

logstash-2018.06.24
logstash-2018.06.25
logstash-2018.06.26

Where is the query supposed to search? Only in the latest? Only in the oldest? In all of them?

It'll search all indexes that match the index name pattern you've given.

Thank you.

Providing in the elasticsearch filter plugin these settings:

result_size => 1
enable_sort => true

Do you think Logstash will return only the first match found in index logstash-2018.06.24 or something else?

Assuming the timestamp is the sort key I'd expect it to return the first document in the first index.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.