ElasticSearch/kibana post data on console and set timestamp to now, now+1m etc without using a pipeline

Ingest pipelines are very handy because they allow you to modify your source document’s content, by adding a new @timestamp field with a dynamic value such as {{_ingest.timestamp}}.

However, if you don’t want to use ingest pipelines, there’s another way using runtime fields and a mapping script.

In your mapping, you need to define your @timestamp date field with a script that will compute the value of the field as the document gets indexed:

PUT test-date
{
  "mappings": {
    "properties": {
      "@timestamp": {
        "type": "date" ,
        "script": "emit(new Date().getTime())"
      }
    }
  }
}

Note that in the script, you’re free to apply any logic you want to store now+1, now+2, etc

Then, you can index a document like you always do but without having to specify the @timestamp field:

POST test-date/_doc
{
  "field": "test"
}

And when you run your search, you can retrieve the value of the dynamically created @timestamp field, like this:

POST test-date/_search
{
  "_source": ["field"],
  "fields": ["@timestamp"]
}

=>

  {
    "_index" : "test-date",
    "_source" : {
      "field" : "test"
    },
    "fields" : {
      "@timestamp" : [
        "2023-03-08T14:49:50.459Z"
      ]
    }
  }

The big difference here is that the runtime field is created and indexed on the fly and stored as a separate field, but your source document is not modified like it was with the ingest pipeline. That’s the biggest difference.

Read more here: Source link