Hi,
we have a property startTime under event and this property is type of date. In the discoverer, when we sort by startTime , data is not getting sorted properly.
Could you please help us on this?
Hi,
we have a property startTime under event and this property is type of date. In the discoverer, when we sort by startTime , data is not getting sorted properly.
Could you please help us on this?
Hi, could you please share the ES mapping for this index pattern? You can do in Dev Tools and send GET /your_index_pattern*/_mapping
.
{"cwl-2019.02.11":{"mappings":{"plt-coresvcs-dev-use1a-esindex":{"properties":{"$event":{"properties":{"ETag":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"Key":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"LastModified":{"type":"date"},"Owner":{"properties":{"DisplayName":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"ID":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}}}},"Size":{"type":"long"},"StorageClass":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"activityScheduledEventDetails":{"properties":{"input":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"resource":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}}}},"author":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"body":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"endTime":{"type":"date"},"endtimestamp":{"type":"date"},"errorDescription":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"errorMessage":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"fileName":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"header":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"headers":{"properties":{"Accept":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"Accept-Encoding":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"Accept-Language":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"CloudFront-Forwarded-Proto":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"CloudFront-Is-Desktop-Viewer":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"CloudFront-Is-Mobile-Viewer":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"CloudFront-Is-SmartTV-Viewer":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"CloudFront-Is-Tablet-Viewer":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"CloudFront-Viewer-Country":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"Content-Type":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"Host":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"User-Agent":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"Via":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"X-Amz-Cf-Id":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"X-Amzn-Trace-Id":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"X-Forwarded-For":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"X-Forwarded-Port":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"X-Forwarded-Proto":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"content-type":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"origin":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}}}},"httpMethod":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"id":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"input":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"isBase64Encoded":{"type":"boolean"},"messageId":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"messageInfo":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"msg":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"msgId":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"multiValueHeaders":{"properties":{"Accept":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"Accept-Encoding":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"Accept-Language":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"CloudFront-Forwarded-Proto":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"CloudFront-Is-Desktop-Viewer":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"CloudFront-Is-Mobile-Viewer":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"CloudFront-Is-SmartTV-Viewer":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"CloudFront-Is-Tablet-Viewer":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"CloudFront-Viewer-Country":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"Content-Type":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"Host":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"User-Agent":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"Via":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"X-Amz-Cf-Id":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"X-Amzn-Trace-Id":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"X-Forwarded-For":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"X-Forwarded-Port":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"X-Forwarded-Proto":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"content-type":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"origin":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}}}},"path":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"previousEventId":{"type":"long"},"requestContext":{"properties":{"accountId":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"apiId":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"domainName":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"domainPrefix":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"extendedRequestId":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"httpMethod":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"identity":{"properties":{"sourceIp":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"userAgent":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}}}},"path":{"type":"text","fields":{"keyword":
{"type":"keyword","ignore_above":256}}},"protocol":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"requestId":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"requestTime":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"requestTimeEpoch":{"type":"long"},"resourceId":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"resourcePath":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"stage":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}}}},"resource":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"serviceSource":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"source":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"src":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"stage":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"startTime":{"type":"date"},"stateExitedEventDetails":{"properties":{"name":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"output":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}}}},"status":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"taskToken":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"timestamp":{"type":"date"},"type":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}}}},"@id":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"@log_group":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"@log_stream":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"@message":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"@owner":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"@timestamp":{"type":"date"},"event":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"request_id":{"type":"text","fields":{"keyword":{"type":"keyword","ignore_above":256}}},"timestamp":{"type":"date"}}}}}}
Thank you for your response.
I was not able to send entire json response because of the limitation in this UI. I have sent in 2 post, if you copy both the post together , that will be the entire response for the mapping query.
Please let me know if this helps.
Hi,
Could anyone please help on this issue?
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
© 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.