# Aggregate filter timeout by event timestamp rather than by system time

**URL:** https://discuss.elastic.co/t/aggregate-filter-timeout-by-event-timestamp-rather-than-by-system-time/63671
**Category:** Logstash
**Created:** [October 22, 2016, 8:49pm UTC](https://discuss.elastic.co/t/aggregate-filter-timeout-by-event-timestamp-rather-than-by-system-time/63671 "2016-10-22T20:49:42Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![Ola-Vish](https://avatars.discourse-cdn.com/v4/letter/o/f07891/32.png) [@Ola-Vish](https://discuss.elastic.co/u/Ola-Vish)
#### Post date: [October 22, 2016, 8:49pm UTC](https://discuss.elastic.co/t/aggregate-filter-timeout-by-event-timestamp-rather-than-by-system-time/63671/1 "2016-10-22T20:49:42Z")

</div>

Hi,

Is it at all possible for the aggregate filter to have the timeout according to a timestamp field in the event itself rather than the system time?

This is important for me because I want to index some old logs and I want the aggregation to be done by the original timestamp.

Thanks for your help!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:33am UTC](https://discuss.elastic.co/t/aggregate-filter-timeout-by-event-timestamp-rather-than-by-system-time/63671/2 "2017-07-06T04:33:13Z")

</div>


