ElasticSearch/kibana post data on console and set timestamp to now, now+1m etc without using a pipeline
Ingest pipelines are very handy because they allow you to modify your source document’s content, by adding a new @timestamp field with a dynamic value such as {{_ingest.timestamp}}.
However, if you don’t want to use ingest pipelines, there’s another way using runtime fields and a mapping script.
In your mapping, you need to define your @timestamp date field with a script that will compute the value of the field as the document gets indexed:
PUT test-date
{
"mappings": {
"properties": {
"@timestamp": {
"type": "date" ,
"script": "emit(new Date().getTime())"
}
}
}
}
Note that in the script, you’re free to apply any logic you want to store now+1, now+2, etc
Then, you can index a document like you always do but without having to specify the @timestamp field:
POST test-date/_doc
{
"field": "test"
}
And when you run your search, you can retrieve the value of the dynamically created @timestamp field, like this:
POST test-date/_search
{
"_source": ["field"],
"fields": ["@timestamp"]
}
=>
{
"_index" : "test-date",
"_source" : {
"field" : "test"
},
"fields" : {
"@timestamp" : [
"2023-03-08T14:49:50.459Z"
]
}
}
The big difference here is that the runtime field is created and indexed on the fly and stored as a separate field, but your source document is not modified like it was with the ingest pipeline. That’s the biggest difference.
Read more here: Source link
