I'm pumping data into ElasticSearch (actually using rsyslog instead of
logstash) into a date-based index with a mapping that stores the
_timestamp. When I go in with Kibana 4.0.1 and start setting it up, it
sees the indexes, but the drop down where you select the time field name is
empty and it will not let me create it. Why is this?
I can create it if I uncheck the box that it's a time-based index and just
enter 'vip*' for the name, but that is not what I want. Below is the
mapping.
The 'timestamp' field inside 'properties' is a textual field from syslog
that is relatively useless for sorting, but it doesn't show up either.
Thanks for any input!
Thank you so much for posting this! Couldn't figure out how to get past
that first screen. Adding the name of my timestamp field into the
metaFields under Advanced solved it.
On Tuesday, March 17, 2015 at 3:39:21 AM UTC-7, Micah Yoder wrote:
For the record, I had to add the _timestamp field into the meta-fields in
the Kibana advanced configuration settings ...
Are you able to apply time filters at kibana 4 dashboards after setting
_timestamp at metafields?
I'm using kibana 4.1 snapshot, _timestamp and setting time filter at top
right (eg. last 3 months to now) at a dashboard simply doesnt work.
On Thursday, March 26, 2015 at 7:51:45 AM UTC+2, ma...@coreyac.com wrote:
Thank you so much for posting this! Couldn't figure out how to get past
that first screen. Adding the name of my timestamp field into the
metaFields under Advanced solved it.
On Tuesday, March 17, 2015 at 3:39:21 AM UTC-7, Micah Yoder wrote:
For the record, I had to add the _timestamp field into the meta-fields in
the Kibana advanced configuration settings ...
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.