# Calculate elapsed time for multiple end events

**URL:** https://discuss.elastic.co/t/calculate-elapsed-time-for-multiple-end-events/205319
**Category:** Logstash
**Created:** [October 25, 2019, 7:36pm UTC](https://discuss.elastic.co/t/calculate-elapsed-time-for-multiple-end-events/205319 "2019-10-25T19:36:34Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![Patrick\_Gell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/patrick_gell/32/56649_2.png) [@Patrick\_Gell](https://discuss.elastic.co/u/Patrick_Gell)
#### Post date: [October 25, 2019, 7:36pm UTC](https://discuss.elastic.co/t/calculate-elapsed-time-for-multiple-end-events/205319/1 "2019-10-25T19:36:34Z")

</div>

Hello,

I have a message driven system where one message is sent to multiple receiver.  
Now I wanted to track the time it takes for every receiver until the message arrives.  
The structure of my log entries looks like:  
`TIMESTAMP SYSTEMID MESSAGEID`  
`20190101 master1 message1 <--- START_TAG`  
`20190101 receiver1 message1 <--- END_TAG`  
`20190101 receiver2 message1 <--- END_TAG`

When I parse my log only for one event is the elapsed\_time calculated. All the other events get tagged with `elapsed_end_without_start`

My question: Is there any solution how I can calculate the elapsed\_time for all of my messages?

My logstash config:

```
grok {
    match => { "SYSTEMID" => "master%{GREEDYDATA}" }
    add_tag => ["taskStarted"]
}

grok {
    match => { "SYSTEMID" => "receiver%{GREEDYDATA}" }
    add_tag => ["taskFinished"]
}

elapsed {
    start_tag => "taskStarted"
    end_tag => "taskFinished"
    unique_id_field => "signalID"
    timeout => 500
    new_event_on_match => false
}

```

Thank you for your help  
Patrick

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [October 25, 2019, 8:58pm UTC](https://discuss.elastic.co/t/calculate-elapsed-time-for-multiple-end-events/205319/2 "2019-10-25T20:58:13Z")

</div>

Instead of doing that with an elapsed filter I would do it using aggregate. Add the timestamp of the master1 message to the map[], then look it up for each receiver message and calculate the duration.

---

<div class="post-metadata">

### Author: ![kkulkarni](https://avatars.discourse-cdn.com/v4/letter/k/4af34b/32.png) [@kkulkarni](https://discuss.elastic.co/u/kkulkarni)
#### Post date: [November 6, 2019, 4:50am UTC](https://discuss.elastic.co/t/calculate-elapsed-time-for-multiple-end-events/205319/3 "2019-11-06T04:50:32Z")

</div>

Hi Patrick,

I had similar use-case and was able to calculate the elapsed time. You need to add aggregate function.

grok {  
match =\> { "SYSTEMID" =\> "master%{GREEDYDATA}" }  
add\_tag =\> ["taskStarted"]  
}

grok {  
match =\> { "SYSTEMID" =\> "receiver%{GREEDYDATA}" }  
add\_tag =\> ["taskFinished"]  
}

elapsed {  
start\_tag =\> "taskStarted"  
end\_tag =\> "taskFinished"  
unique\_id\_field =\> "signalID"  
timeout =\> 500  
new\_event\_on\_match =\> false  
}  
if "in1" in [tags] and "elapsed" in [tags] {  
aggregate {  
task\_id =\> "%{signalID}"  
code =\> "map['report'] = [(event['elapsed\_time']\*1000).to\_i]"  
map\_action =\> "create"  
}  
}

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 4, 2019, 4:50am UTC](https://discuss.elastic.co/t/calculate-elapsed-time-for-multiple-end-events/205319/4 "2019-12-04T04:50:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
