I am new to Elastic Stack and I have two queries,
Indices status in Kibana - we are indexing all the data from servers to ElasticSearch using Fluentd agent. When we did a POC setup, we were able to search data in Kibana and indices status was green but when the same configurations are used in Prod env, we are unable to search data in Kibana and indices status is showing red. Where and what we need to check to fix this?
Even though time format is defined in the td-agent.conf file, timestamp filter is not reflected in the index pattern on the Kibana. What additional configuration we need to make to fix it? Meta_field was edited in the advanced settings to add the timestamp filter but search didn't work, so reverted this change.