I am doing this query but it is returning documents older:
get /ueb-metrics-*/_search
{
"query": {
"range": {
"timestamp": {
"gte": "now-1d"
}
}
}
}
returns docs from months ago like:
hits": [
{
"_index": "ueb-metrics-2017.01",
"_type": "object",
"_id": "d6b3ec11-ecd9-47e2-842a-99574ff8b3a0_storage_2017.01.18_14.00",
"_score": 1,
"_source": {
"type": "storage",
"asset_tag": "d6b3ec11-ecd9-47e2-842a-99574ff8b3a0",
"timestamp": "2017-01-18T14:00:01.694245+01:00",
"storage": {
"name": "Internal",
"mb_free": 135978,
"mb_size": 153521,
"mb_used": 17543,
"mb_to_purge": 3166,
"percent_used": "11.43%",
"average_write_speed": "N/A",
"dedup": "N/A"
}
}