ES version 7.17.3
Fluentd config is as below:
time_key timestamp time_format %Y-%m-%dT%H:%M:%S.%N%Z
which takes nano seconds into consideration and data is stored properly in elasticsearch as:
But default data type in mapping properties of index is "date"
This is creating problem in sorting, as type "date" considers only milli seconds and documents are being sorted in wrong order for whom the difference is at nano second level.
How do I set the default date type as "date_nanos" ?
I know I can delete and re-create the index and type date_nanos and reindex it, but I cannot do this in production. So basically, by default it should take date_nanos.
Please suggest how I can configure this.
Also I am using helm charts, so configuration to be done at ES chart possible?