Skip to content

Opensearch

Define timestamp field

Define file type with format in new index

PUT /test-01 
{
  "mappings" : {
    "properties" :  {
      "event_time" : {
        "type" : "date",
        "format": "yyyy-MM-dd HH:mm:ss.SSSSSSSSS Z z||strict_date_optional_time ||epoch_millis"
      }
    }
  }
}

Add example document

POST /test-01/_doc
{
  "message" : "test-message1",
  "event_time": "2023-10-22 10:40:06.298656213 +0000 UTC"
}