How to write using Kibana search bar

Hi Experts,

This is the data between October and December of something.
I want to find data that have accessed by October but never accessed in December.
If I do what I think, the result should show b only. But it did not work well.

so I wrote in search bar like
@timestamp:[* TO 2018-10-31T23:59:59.999Z ] AND NOT @timestamp:[2018-12-01T00:00:00.000Z TO now ]

This is result.

What's the problem?

Hey @a86236df74eecab0f8a3,

I don't think this is currently possible as-is. What you could do is write a script to enrich your existing data (perhaps using the re-index API), and add a new field which indicates whether or not the entity was accessed between a specific time range.

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.