# Calculating time between two events from same request id

**URL:** <https://discuss.elastic.co/t/calculating-time-between-two-events-from-same-request-id/354880>\
**Category:** Kibana\
**Created:** [March 6, 2024, 9:10pm UTC](https://discuss.elastic.co/t/calculating-time-between-two-events-from-same-request-id/354880 "2024-03-06T21:10:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohammad\_Alam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammad_alam/32/132416_2.png) [@Mohammad\_Alam](https://discuss.elastic.co/u/Mohammad_Alam)\
**Post date:** [March 6, 2024, 9:10pm UTC](https://discuss.elastic.co/t/calculating-time-between-two-events-from-same-request-id/354880/1 "2024-03-06T21:10:53Z")

</div>

I am new to Elastic and Kibana so any help here would be helpful.

I have logs coming in to elastic where a request with a unique id will go through various action stages, from request created to request approved to request granted. I am trying to figure out the best way to calculate time elapsed between states for each of the unique ids using the timestamp field. So for example request with id 1 comes in at 13:00:00, gets approved at 13:05:02 and granted at 13:08:24, what is the best way to calculate that and then visualize it?

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [March 19, 2024, 10:19pm UTC](https://discuss.elastic.co/t/calculating-time-between-two-events-from-same-request-id/354880/2 "2024-03-19T22:19:55Z")

</div>

It sounds like the documents in the Elasticsearch index pertain to timestamps that pertain to changes in "actions", and different documents are stored for the same individual action to track the change in the stage value. If so, then the data is "event-centeric" as it tracks events when things changed, and what changed in the event.

I recommend looking into the Transforms feature of Elasticsearch to pivot the data into a new index that is entity-centric around actions. Under that new design, each action will be a single document, with specific fields to track when the state changed. A transform is a continuous process that keeps the destination index up-to-date as new data comes in.

You can learn more about the Transforms feature here: [https://www.elastic.co/guide/en/elasticsearch/reference/current/transform-overview.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/transform-overview.html)

---

<div class="post-metadata">

**Author:** ![Mohammad\_Alam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammad_alam/32/132416_2.png) [@Mohammad\_Alam](https://discuss.elastic.co/u/Mohammad_Alam)\
**Post date:** [March 20, 2024, 3:38am UTC](https://discuss.elastic.co/t/calculating-time-between-two-events-from-same-request-id/354880/3 "2024-03-20T03:38:40Z")

</div>

Thank you, i ended up doing exactly this. I created a transform that created one entry for an event with the start and end time as fields and then calculated the difference between the two via scripted field.

---

<div class="post-metadata">

**Author:** ![tsullivan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsullivan/32/31077_2.png) [@tsullivan](https://discuss.elastic.co/u/tsullivan)\
**Post date:** [March 20, 2024, 2:45pm UTC](https://discuss.elastic.co/t/calculating-time-between-two-events-from-same-request-id/354880/4 "2024-03-20T14:45:57Z")

</div>

Glad to hear! Thanks for the follow-up.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 17, 2024, 2:46pm UTC](https://discuss.elastic.co/t/calculating-time-between-two-events-from-same-request-id/354880/5 "2024-04-17T14:46:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
