I have a full date field (epoch_second), but I also want to be able to query based on the just the time, so I made another date field ("time" with "hour_minute_second" format).
By default, Kibana shows this "time" field values as full dates with the epoch day, e.g. "1970-01-01T21:35:49.000Z". That's fine (since you can customize the display), but I can't find a way to query based on this field.
Just to start more simply, let's try to find "late night" events, say "20:00:00" to "23:59:59".
Here are some things that I've tried:
- clicking the "Filter for value" icon next to the "time" column. This throws a "Bad Request" exception (even doing that on the main datetime field throws the same error).
- querying for 'time > 1970-01-01T20:00:00.000Z'. This gives the error: Expected AND, OR, end of input, whitespace but ":" found
- querying for 'time > "1970-01-01T20:00:00.000Z"', 'time > "20:00:00.000Z"' and pretty much anything that looks like a time throws a "Bad Request"
So, what's the secret sauce?
The real request would be for 10PM-6AM, which I imagine will require two queries (>10 OR <6). If there's another way, please let me know.