I have indexed a base64 encoded attachment using latest ingest-attachment plugin.
My elsaticsearch and kibana environment is below.
[root@filebeat elasticsearch]# rpm -qa | grep kibana
kibana-5.0.1-1.x86_64
[root@filebeat elasticsearch]# rpm -qa | grep elasticsearch
elasticsearch-5.0.1-1.noarch
However, indexed document is not searchable from Kibana Discovery.
Doument definitely exists when I search from the query.
{
"took": 6,
"timed_out": false,
"_shards": {
"total": 5,
"successful": 5,
"failed": 0
},
"hits": {
"total": 2,
"max_score": 1,
"hits": [
{
"_index": "test",
"_type": "test",
"_id": "1",
"_score": 1,
"_source": {
"date": "2016-11-17T18:50:00",
"data": "H4sICFVwLVgAA2RhdGUudHh0AAvJKFXwyy9TMDRXMLCwMjWxMjFVCA1xVjAyMDTjAgBpNz/EHQAAAA==",
"attachment": {
"content_type": "application/gzip",
"content_length": 0
}
}
},
{
"_index": "test",
"_type": "test",
"_id": "3",
"_score": 1,
"_source": {
"date": "2016-11-17T18:55:00",
"data": "H4sICFVwLVgAA2RhdGUudHh0AAvJKFXwyy9TMDRXMLCwMjWxMjFVCA1xVjAyMDTjAgBpNz/EHQAAAA==",
"attachment": {
"content_type": "application/gzip",
"content_length": 0
},
"subject": "My First attachment",
"from": "creationline@localhost.localdomain",
"to": "root@localhost.localdomain"
}
}
]
}
}
Below is the query.
GET test/test/_search
{
"query" : {
"range" : {
"date" : {
"gte" : "now-1y"
}
}
}
}
May I ask how can I debug the kibana query?