If the primary timestamp field of your index vogo-database-2 is different from @timestamp, you can specify it in your query as in: .es(index="vogo-database-2", timefield="YOUR_TIMEFIELD")
You should be able to draw these 5 lines with just one query using the split argument to .es(): .es(index="vogo-database-2", timefield="YOUR_TIMEFIELD", split="status:10")
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.