Now have have another issue that has popped up. After resolving the last issue by modifying the memory settings in Elasticsearch, I no longer can see messages. It appears that messages are being processed, but not viewable. The last one viewable are from yesterday morning.
If you expand your time range in search for all messages, what do you get? Also, since you seemed to have quite a backlock and things were full, do you still have a backlog of messages or unprocessed messages?
I got it figured out. I didn’t notice the little things like the server time being about 12 hours off. I corrected the time and now I can see the logs coming in.