# Aggregation filter timeout settings

**URL:** <https://discuss.elastic.co/t/aggregation-filter-timeout-settings/196208>\
**Category:** Logstash\
**Created:** [August 21, 2019, 11:38pm UTC](https://discuss.elastic.co/t/aggregation-filter-timeout-settings/196208 "2019-08-21T23:38:20Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![jratliff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jratliff/32/52746_2.png) [@jratliff](https://discuss.elastic.co/u/jratliff)\
**Post date:** [August 23, 2019, 1:49am UTC](https://discuss.elastic.co/t/aggregation-filter-timeout-settings/196208/4 "2019-08-23T01:49:20Z")

</div>

I'm still having trouble understanding when logstash will timeout an aggregation when the timeout\_timestamp\_field is set.

If logstash has parsed the entire log file, and I don't give it any more log files, but it is still waiting on a timeout for an aggregation, what is that timeout?

I have log files that take place over the course of a single day.  
The timeout value is 86400 (1 day)  
The inactivity\_timeout is set to 330 (5.5 minutes).

I thought all the in-memory logstash aggregations would timeout 5.5 minutes after the last event was read. But I'm still watching it push aggregation maps as events after an hour. So, what is the timeout when there are no new events to consider?

---

_[View the full topic](https://discuss.elastic.co/t/aggregation-filter-timeout-settings/196208)._
