One Deata view @timestamp alarm

This request queries Elasticsearch to fetch the documents.

Search session id: d53c937d-ef25-4122-862c-9cc00f861186

Node
c60fcARCT5m2jef2_njmog
Reason
error fetching [structured.@timestamp]: Field [structured.@timestamp] of type [flattened] doesn't support formats.
Caused by type
illegal_argument_exception
Caused by reason
Field [structured.@timestamp] of type [flattened] doesn't support formats.

Please help for check and fix. I have changed the Logstash pipelines … and my teammate change some.

Welcome to the community.

It seams something not OK with data format which LS have sent to ES. Have you check what is the @timestamp format? Also make sure that is acceptable on the ES side - mapping or template .

Can you please provide more details?

Welcome to the forum.

Errr ..... telling us what you changed, and what your colleagues changed, will give us more of a clue? Please. and the actual query/search you did will be useful too.

And it's unlikely we can actually fix your issue, though we can possibly tell you what you need to change/adapt. But first you need help us help you by supplying more details.

Thanks fixed .that is Logstash pipelines changed and the mapping structured as flattened.

2 Likes