I am not sure what logstash YYYY.MM.dd is based on.
I'm in asia/seoul area and I also sent a message at 1am. The 13th was 1:00 a.m. on the 14th, but there was no newly created 14-day index in elasticsearch.
I searched for other similar questions and saw that @timestamp is the standard.
Obviously, the timestamp was 14 days, but there was no new 14-day index.
If I am doing something wrong, can I make YYYY.MM.dd into the future if I change @timestamp into the future using logstash's date filter?
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.