# Stream live not updating

**URL:** <https://discuss.elastic.co/t/stream-live-not-updating/163734>\
**Category:** Logs\
**Created:** [January 10, 2019, 12:33pm UTC](https://discuss.elastic.co/t/stream-live-not-updating/163734 "2019-01-10T12:33:58Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![aviator](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@aviator](https://discuss.elastic.co/u/aviator)\
**Post date:** [January 10, 2019, 12:33pm UTC](https://discuss.elastic.co/t/stream-live-not-updating/163734/1 "2019-01-10T12:33:58Z")

</div>

Hi

When using the Stream Live feature the logs do not get updated in realtime, the logs are there because a page refresh displays them.  
I think the key is that each time I load up the Logs app the newest/latest entry is:  
2019-12-31 23:59:53.000 INFO: xxxxx daemon running

Everything behind that is up to date i.e.  
2019-01-10 12:29:21.587 Jan 10 12:29:20 localhost

So I guess something is stuck somewhere - is there a file that checkpoints and needs clearing or similar?

Regards

Ed

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 10, 2019, 3:08pm UTC](https://discuss.elastic.co/t/stream-live-not-updating/163734/2 "2019-01-10T15:08:55Z")

</div>

Hi @aviator,

can you check whether the timestamp in your original log messages contain a year?

---

<div class="post-metadata">

**Author:** ![aviator](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@aviator](https://discuss.elastic.co/u/aviator)\
**Post date:** [January 10, 2019, 3:19pm UTC](https://discuss.elastic.co/t/stream-live-not-updating/163734/3 "2019-01-10T15:19:33Z")

</div>

one does and one does not, perhaps the latter is the one being filtered on?

"@timestamp": "2019-01-10T15:11:36.000Z",  
"system": {  
"syslog": {  
"hostname": "xxxxx",  
"pid": "13793",  
"program": "haproxy(HAProxy)",  
"message": "INFO: haproxy daemon running",  
"timestamp": "Jan 10 15:11:36"

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 10, 2019, 3:39pm UTC](https://discuss.elastic.co/t/stream-live-not-updating/163734/4 "2019-01-10T15:39:46Z")

</div>

Yes, `timestamp` is what is read from the text and `@timestamp` is how Elasticsearch has interpreted it at indexing time. So the problem is that the original timestamp is ambiguous and its interpretation depends on the time of indexing. This becomes obvious when crossing into a new year.

My current recommendation would be to fix the incorrect timestamps using a [update-by-query](https://www.elastic.co/guide/en/elasticsearch/reference/current/docs-update-by-query.html) operation. Adapting the log producer's timestamp format to include a year would prevent that from happening again at the beginning of the next year.

We're currently discussing other ways in which we can make such situations less problematic.

---

<div class="post-metadata">

**Author:** ![aviator](https://avatars.discourse-cdn.com/v4/letter/a/9de053/32.png) [@aviator](https://discuss.elastic.co/u/aviator)\
**Post date:** [January 10, 2019, 3:49pm UTC](https://discuss.elastic.co/t/stream-live-not-updating/163734/5 "2019-01-10T15:49:21Z")

</div>

Ahh many thanks, that all makes perfect sense now! Will have a look the the update query and see what can be done. Going forward this is something I will out for when adding log streams,

again, my thanks to you for concise and accurate assistance

Regards

Ed

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [January 10, 2019, 3:53pm UTC](https://discuss.elastic.co/t/stream-live-not-updating/163734/6 "2019-01-10T15:53:02Z")

</div>

We have created [beats issue #9995](https://github.com/elastic/beats/issues/9995) to track this scenario.

Let us know if the update query doesn't work as hoped.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2019, 3:53pm UTC](https://discuss.elastic.co/t/stream-live-not-updating/163734/7 "2019-02-07T15:53:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
