Feed lost data to ELK

Hi all,

I' am having an production incident, we loss 12 hours of data due to some incident, now the service is back to normal and elastic is serving the data, but we need to fill the loss data gap. We have the relevant log files. How can we feed these missing data ?
Here is an screenshot of the kibana.
Appreciate your valuable inputs on this :slightly_smiling_face:.


Thank you,

I suspect this is more of a question for the logstash forum, it being upstream of elasticsearch.

Created the topic in the logstash forum.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.