Hello, When I write data to a summary index, the timestamp (_time) always follows the earliest time. For example, if my daily scheduled search runs at 1am today, 9/15/2024, to write the last 24-hou...
See more...
Hello, When I write data to a summary index, the timestamp (_time) always follows the earliest time. For example, if my daily scheduled search runs at 1am today, 9/15/2024, to write the last 24-hour data to a summary index, the time stamp (_time) will be 9/14/2024. When I search the summary index in the last 24 hours, the result will be empty because it's always 24 hours behind, so I have to modify the search time to the last 2-day to see the data. Is it a best practice to keep the timestamp as the earliest time, or do you modify the timestamp to the search time? In my example, if I modify the timestamp to the search time, the time stamp would be 9/15/2024 1 a.m. Please suggest. Thank you so much for your help.