Hello! I need help with a problem I'm having between 2 versions of ELK. These versions correspond to two different platforms that consume data from the same source.
The first image corresponds to an ELK stack 7.9, where we are seeing the sum of values of a specific field day by day.
In the second image we see the same example but on an ELK stack 7.17, and we have values that do not agree with the previous graph.
In both infrastructures the processes are the same. Same data source, same processing and same ingestion from logstash. We are not applying any filter to the visualizations, and both data views (index patterns) are the same.
For some reason that I have not been able to discover, the values differ on both platforms, when they should be identical.
I have reviewed the configurations of both clusters, both logstash, and the same ones are being implemented in both cases.
Any advice on where else I could check?
Thank you so much!!