# Calculate Unix timestamp difference in kibana

**URL:** <https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241>\
**Category:** Kibana\
**Created:** [July 12, 2023, 2:56pm UTC](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241 "2023-07-12T14:56:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Babu72](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@Babu72](https://discuss.elastic.co/u/Babu72)\
**Post date:** [July 12, 2023, 2:56pm UTC](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241/1 "2023-07-12T14:56:13Z")

</div>

Hi All,  
I need help for new scripted field to calculate Unix timestamp difference in kibana as a Metric

```auto
stop_timestamp :
start_timestamp :
output: hh:mm:ss:SS:SS

```

```auto
1 = 1 Nanosecond
1000 = 1 Microsecond
1000000 = 1 Millisecond
1000000000 = 1 second

```

I am using Kibana 7.17

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [July 12, 2023, 5:21pm UTC](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241/2 "2023-07-12T17:21:41Z")

</div>

Have you tried:

```auto
doc['stop_timestamp'].value - doc['start_timestamp'].value

```

---

<div class="post-metadata">

**Author:** ![Babu72](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@Babu72](https://discuss.elastic.co/u/Babu72)\
**Post date:** [July 12, 2023, 7:31pm UTC](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241/3 "2023-07-12T19:31:13Z")

</div>

> [@tsullivan](#):
>
> `doc['stop_timestamp'].value - doc['start_timestamp'].value`

Thanks for your reply, as my requirement supports unix timetimestamp I tried :

```auto
def inc_factor;
	
if(doc['timeline_increment_factor'].value){
 inc_factor = (doc['timeline_increment_factor'].value);
} else {
 inc_factor = 1;
}
if (doc['duration'].value) { 
    return Math.floor(((doc['duration'].value) * inc_factor)/1000000000) ;
}
return 0;

```

Error :

```auto
org.elasticsearch.search.lookup.LeafDocLookup.get(LeafDocLookup.java:100)",
            "org.elasticsearch.search.lookup.LeafDocLookup.get(LeafDocLookup.java:28)",
            "if(doc['timeline_increment_factor'].value){\r\n ",
            " ^---- HERE"

```

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [July 12, 2023, 9:56pm UTC](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241/4 "2023-07-12T21:56:23Z")

</div>

Is the extra complexity you're adding intended to solve a special thing needed for Unix timestamps? I am not following what "timeline increment factor" has to do with calculating a difference of Unix timestamps.

A unix timestamp is just one way of formatting a `date`, the value being the number of seconds since January 1, 1970 - aka the Unix epoch. You said you have start and stop timestamp fields, which are mapped in Elasticsearch as `date` or some numeric representation of the number of seconds since the Unix epoch. Either way, I think my example should suffice for your use case. If you have two different fields that are a number of seconds, they are relatable and if you need their difference you can subtract one from the other.

Could you give a real example of what your document fields and values look like, and what mappings you have?

---

<div class="post-metadata">

**Author:** ![Babu72](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@Babu72](https://discuss.elastic.co/u/Babu72)\
**Post date:** [July 13, 2023, 5:13am UTC](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241/5 "2023-07-13T05:13:49Z")

</div>

from document the idea is to get the value in 'seconds' and sum(add) all the documents and convert the final value into hh:mm:ss:SS

```auto
Example:
"stop_timestamp": 1629098169,
"start_timestamp": 1629095674,
"timeline_increment_factor": 1000000000 (the timeline factor varies to document , it can be nano, milli, micro and second)

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2023, 5:13am UTC](https://discuss.elastic.co/t/calculate-unix-timestamp-difference-in-kibana/338241/6 "2023-08-10T05:13:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
