save the timestamp from your message in the timestamp field
ensure that the timestamp in your message is saved as timestamp (in elasticsearch) now you can search on the time in the field when you for example select search by keyword “one week” and add in the search bar your timestamp field …
nope - this might only get a little tricky when it comes to retention. As you might have indices holding data for several years and not only days … but if you keep that in mind.
For Graylog it is not a problem to have data ingested from the past.