# Calculate time using timestamp!

**URL:** <https://discuss.elastic.co/t/calculate-time-using-timestamp/24123>\
**Category:** Elasticsearch\
**Created:** [June 22, 2015, 7:50pm UTC](https://discuss.elastic.co/t/calculate-time-using-timestamp/24123 "2015-06-22T19:50:16Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Smasell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smasell/32/43483_2.png) [@Smasell](https://discuss.elastic.co/u/Smasell)\
**Post date:** [June 22, 2015, 7:50pm UTC](https://discuss.elastic.co/t/calculate-time-using-timestamp/24123/1 "2015-06-22T19:50:16Z")

</div>

Hi, guys!!!  
I want to calculate how much time a user has spent in the game.  
I have my documents with fields:  
timestamp,  
message.  
Message field can be 2 different types: "log in" and "log out". Difference in time between "log in" and "log out" is the time my user has spent in my game. Is it possible to calculate the time the user has spent in the game for a month?

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [June 23, 2015, 3:02am UTC](https://discuss.elastic.co/t/calculate-time-using-timestamp/24123/2 "2015-06-23T03:02:13Z")

</div>

As I understand your question

There is not any concept of SUB Searches (like in SQl) I don't think you will be able to do this, This data would have to be processed by the app making the request and not by elastic search. (IE get a list of all login's and then query all the logouts and compare)

You may find this pages of interest, but I think this is more complicated that what your trying to accomplish

[http://joelabrahamsson.com/grouping-in-elasticsearch-using-child-documents/](http://joelabrahamsson.com/grouping-in-elasticsearch-using-child-documents/)

---

<div class="post-metadata">

**Author:** ![Smasell](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/smasell/32/43483_2.png) [@Smasell](https://discuss.elastic.co/u/Smasell)\
**Post date:** [June 23, 2015, 9:16am UTC](https://discuss.elastic.co/t/calculate-time-using-timestamp/24123/3 "2015-06-23T09:16:10Z")

</div>

@eperry  
But if I have 2 documents (one with"log in"and another with "log out") can I get time between this 2 documents using timestamp? (For example log out.timestamp - log in.timestamp)?

---

<div class="post-metadata">

**Author:** ![colings86](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/colings86/32/44960_2.png) [@colings86](https://discuss.elastic.co/u/colings86)\
**Post date:** [June 23, 2015, 9:48am UTC](https://discuss.elastic.co/t/calculate-time-using-timestamp/24123/4 "2015-06-23T09:48:04Z")

</div>

You will probably find this talk by @Mark_Harwood interesting. Here he presents a way of answering these exact questions by indexing your documents in an "entity-centric" (in your case it would be user-centric) way

[https://www.elastic.co/elasticon/2015/sf/building-entity-centric-indexes](https://www.elastic.co/elasticon/2015/sf/building-entity-centric-indexes)

---

<div class="post-metadata">

**Author:** ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)\
**Post date:** [June 23, 2015, 12:05pm UTC](https://discuss.elastic.co/t/calculate-time-using-timestamp/24123/5 "2015-06-23T12:05:13Z")

</div>

Also, if you are a Logstash user, you can have a look at this new logstash plugin: [https://github.com/logstash-plugins/logstash-filter-aggregate](https://github.com/logstash-plugins/logstash-filter-aggregate) which could help you to generate that prior indexing your doc.

Might help.

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [June 24, 2015, 2:04am UTC](https://discuss.elastic.co/t/calculate-time-using-timestamp/24123/6 "2015-06-24T02:04:32Z")

</div>

@dadoonet  
That is a cool idea of a plugin, I will definitely check that out. I presume my "Task\_ID" could be a users Jsession id.

@Smasell right comparing 2 documents are not possible (Though maybe you can find a aggregator or as @Dadoonet suggest Merge the Login and logout to one document. At that point you can compare 2 fields with scripted field.

There may be other possibilities but extend outhside the actual Elasticsearch Query Language.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:05am UTC](https://discuss.elastic.co/t/calculate-time-using-timestamp/24123/7 "2017-07-06T00:05:46Z")

</div>


