# Calculate timestamp duration to next document

**URL:** <https://discuss.elastic.co/t/calculate-timestamp-duration-to-next-document/297244>\
**Category:** Logstash\
**Created:** [February 15, 2022, 1:04pm UTC](https://discuss.elastic.co/t/calculate-timestamp-duration-to-next-document/297244 "2022-02-15T13:04:52Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 15, 2022, 5:53pm UTC](https://discuss.elastic.co/t/calculate-timestamp-duration-to-next-document/297244/2 "2022-02-15T17:53:08Z")

</div>

There is [derivative aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline-derivative-aggregation.html), but there is no function like that for documents.

Perhaps [Logstash Aggregation Filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html) could make it feasible somehow.

Though I'm not sure @@map is also usable in recent Logstash, this may also help you.

> [@Keeping global variables in LS?!](https://discuss.elastic.co/t/keeping-global-variables-in-ls/39908/6):
>
> Camden - Thx for sharing. Looking at this code with my beginner Ruby skills, it looks like you initialize a Map structure, into which you add a Year value which you extract from the Event's timestamp. The Else clause seems to replace all instances of Jan,Feb, .... Dec with the Year that you've stored in the map previously or current Year. I understand the concept in general. Some questions on your example: At what point in the config did you insert this section of the custom code? What …

---

_[View the full topic](https://discuss.elastic.co/t/calculate-timestamp-duration-to-next-document/297244)._
