# Aggregate logs of different grok matches

**URL:** <https://discuss.elastic.co/t/aggregate-logs-of-different-grok-matches/320901>\
**Category:** Logstash\
**Created:** [December 9, 2022, 4:20pm UTC](https://discuss.elastic.co/t/aggregate-logs-of-different-grok-matches/320901 "2022-12-09T16:20:24Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![stefanocog](https://avatars.discourse-cdn.com/v4/letter/s/5fc32e/32.png) [@stefanocog](https://discuss.elastic.co/u/stefanocog)\
**Post date:** [December 9, 2022, 4:20pm UTC](https://discuss.elastic.co/t/aggregate-logs-of-different-grok-matches/320901/1 "2022-12-09T16:20:24Z")

</div>

Hi, I apologize in advance if the request appears incorrect  
I need calculate the time difference between a request and response of a REST service, this service produce two logs, one for request e and one for response and have a different structure, I am therefore forced to use two grok filters.  
With this premise, below is an example of how it could be

```auto
filter {
  grok {
      # grok service
      match => { "message" => "\"%{GREEDYDATA:url}/service-name\"" }
      add_field => ["name", "match-service"]
  }
  if [name] == "match-service" {
      # grok request service
      grok {
          match => { "message" => "\"%{TIMESTAMP_ISO8601:timestamp}\"\|\"transId: %{GREEDYDATA:transactionId}\"\|\"reqId: %{GREEDYDATA:requestId}\"\|...." }
          add_field => ["service", "request"]
      }
      if [service] == "request" {
          date {
          match => ["timestamp", "yyyy-MM-dd HH:mm:ss:SSS"] target => "t1" 
          }
      }
      # grok response service
      grok {
          match => { "message" => "\"%{TIMESTAMP_ISO8601:timestamp}\"\|\"transId: %{GREEDYDATA:transactionId}\"\|\"resId: %{GREEDYDATA:responseId}\"\|...." }
          add_field => ["service", "response"]
      }
      if [service] == "response" {
          date {
          match => ["timestamp", "yyyy-MM-dd HH:mm:ss:SSS"] target => "t2" 
      }
    }
  }
}

```

Could I aggregate the logs to get the difference between t2 and t1 ? I think it can be done with `aggregate` setting `transactionId` as `task_id` but I don't know if it's possible

Thanks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 9, 2022, 7:51pm UTC](https://discuss.elastic.co/t/aggregate-logs-of-different-grok-matches/320901/2 "2022-12-09T19:51:43Z")

</div>

> [@stefanocog](#):
>
> I don't know if it's possible

It is. There is an example of something like that [here](https://discuss.elastic.co/t/how-to-calculate-and-present-times-between-logs/313324/2).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 6, 2023, 7:52pm UTC](https://discuss.elastic.co/t/aggregate-logs-of-different-grok-matches/320901/3 "2023-01-06T19:52:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
