I am expected to have 1000 documents in the index named develop1000, that's the result of GET develop1000/_count but the problem is when I check in Discover, I only have 992 hits.
What could be the problem please? and how to investigate the issue? I have the same problem in another index!
Perhaps some of the documents timestamps are not correct and inside / outside your time window in Discover OR somehow on the reindex the timestamp failed and those docs don't have a timestamp.
Also with 1000 documents just run the reindex in the foreground wait_for_completion=true and see if you get any errors
For the time field it's during October 2020 for all events, in discover I set the time to look for 2 years ago to be sure to get all events. But as you suggested the problem is that the field @timestamp is missing for 8 documents and checked that using the following query, as you pointed out in your answer:
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant
logo are trademarks of the
Apache Software Foundation
in the United States and/or other countries.