Hello There I have an ELK stack running with filebeat but I have an issue when I save a search for a
a specific query I am unable to view results in the last 15 and 30 minutes and so on and only start to see results when I set the time to 7 days or more.
I am happy to share my configurations if needed.
Thanks