I'm making a table in Kibana and one of the things I want to be able to show is the count of documents that have the field "outcome" with a value "OVERRIDE" and a date range between some date and now.
The outcome filter is fine; I just use outcome:OVERRIDE, but the date range filter is tripping me up. I've tried using the following format:
date_time:[successful_date_time TO now]
However this doesn't work even though I've specified successful_date_time (which is a scripted field) to have the format "YYYY-MM-DDTHH:mm:ss.SSS" as the moment.js format pattern. An example output from this field would be 2017-10-17T15:52:12.647 , and when I use this value manually for the starting point of the range, i.e. date_time:[2017-10-17T15:52:12.647 TO now], the query works fine, even though successful_date_time outputs this value. Is there a way to use this scripted field as a range marker for my query?