# Calculating duration

**URL:** <https://discuss.elastic.co/t/calculating-duration/296472>\
**Category:** Elasticsearch\
**Created:** [February 7, 2022, 1:27pm UTC](https://discuss.elastic.co/t/calculating-duration/296472 "2022-02-07T13:27:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rusty\_cole](https://avatars.discourse-cdn.com/v4/letter/r/a4c791/32.png) [@rusty\_cole](https://discuss.elastic.co/u/rusty_cole)\
**Post date:** [February 7, 2022, 1:27pm UTC](https://discuss.elastic.co/t/calculating-duration/296472/1 "2022-02-07T13:27:20Z")

</div>

Hi,  
I am not sure if this can be achieved, I have the following query:

```auto
GET /winlogbeat-7.14.0-2022.02.03-000001/_search
{
  "query": {
    "match_all": {}
  },
  "aggs": {
    "bulks": {
      "terms": {
        "field": "winlog.event_data.TargetLogonId",
        "size": 10
      },
  "aggs": {
    "bulks": {
      "terms": {
        "field": "winlog.event_data.TargetUserName",
        "size": 10
      },
        "aggs": {
    "bulks": {
      "terms": {
        "field": "host.name",
        "size": 10
      },
      "aggs": {
        "orders": {
          "top_hits": {
            "size": 10
          }
        }
      }
    }
  }
  }
  }
  }
  }
  }

```

From the query results I need to calculate the following:  
Where ever the field - winlog.event\_id=4624 appears, this should be the start time(from the timestamp).  
Where ever the field - winlog.event\_id=4634 appears, this should be the end time.  
And than I need to calculate the duration (difference) .  
Is there a way to achieve that?

Thanks!

---

<div class="post-metadata">

**Author:** ![Tomo\_M](https://avatars.discourse-cdn.com/v4/letter/t/848f3c/32.png) [@Tomo\_M](https://discuss.elastic.co/u/Tomo_M)\
**Post date:** [February 9, 2022, 12:16pm UTC](https://discuss.elastic.co/t/calculating-duration/296472/2 "2022-02-09T12:16:19Z")

</div>

Are `winlog.event_id=4624` and `winlog.event_id=4634` unique for each [`winlog.event_data.TargetLogonId`, `winlog.event_data.TargetUserName`, `host.name`] buckets? Or are there several start and end events in the bucket and you have to calculate multiple duration.

Anyway, such customized aggregation could be implemented using [scripted metric aggregation](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-metrics-scripted-metric-aggregation.html).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2022, 12:16pm UTC](https://discuss.elastic.co/t/calculating-duration/296472/3 "2022-03-09T12:16:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
