I used logstash to collect the netflow and them import it into kibana,The index is as follows:
But i have found something wired,In kibana i created a table to analyze the src ip address and order by the total bytes.
We can compare these two screenshots , the only difference between them is the index is different.
My expectation is these two result should be the same.Because the time is the same.But Why they are different ? And i think the first one is the correct one since all the data today should be stored in the index netflow-2017.12.16.
And how can i fix the issue , because it's impossible for me to create so many indexes every day