How to get the max timestamp of an elastic search index?

(Ranganath Nangineni) #1


I have this requirement to verify the gap between logstash and elasticsearch processing .
For this , I need to get the max timestamp of the recent index entry.

Any input from the community regrading this ?

(Christian Dahlqvist) #2

Run a max aggregation on the @timestamp field.

(Ranganath Nangineni) #3

Thanks for the update.

The output is showing all the metadata , how can I remove the metadata just to get the required value string .
Say :slight_smile:

curl -XGET "http://localhost:9200/xyzindexpattern-*/_search?size=0" -H 'Content-Type: application/json' -d'

"aggs": {
"max_timestamp": {
"max": {
"field": "@timestamp"

in this I just need only "2018-05-28T11:40:51.411Z" should be displayed as the output.

(Christian Dahlqvist) #4

I think you will need to parse it out from that response.

(system) #5

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.