# Calculating time diff between @timestamp and document date field

**URL:** <https://discuss.elastic.co/t/calculating-time-diff-between-timestamp-and-document-date-field/201918>\
**Category:** Elasticsearch\
**Created:** [October 2, 2019, 9:12am UTC](https://discuss.elastic.co/t/calculating-time-diff-between-timestamp-and-document-date-field/201918 "2019-10-02T09:12:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Josip\_Cagalj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josip_cagalj/32/42899_2.png) [@Josip\_Cagalj](https://discuss.elastic.co/u/Josip_Cagalj)\
**Post date:** [October 2, 2019, 9:12am UTC](https://discuss.elastic.co/t/calculating-time-diff-between-timestamp-and-document-date-field/201918/1 "2019-10-02T09:12:35Z")

</div>

HI,  
I'm having trouble calculating time diff (in seconds) between @timestamp and 'eventTime' date field using script field inside search query.  
My mappings for 'eventTime' field is:

> ```
> "mapping": {
> "dynamic": "false",
> "properties": {
> "eventTime": {
> "type": "date"
> }
> }
> }
> 
> ```

and script field inside search query looks like this:

> ```
> "script_fields": {
> "time_diff1": {
> "script": {
> "lang": "painless",
> "source": "(doc['@timestamp'].value.toInstant().toEpochMilli() - doc.eventTime.value.toInstant().toEpochMilli()) / 1000"
> }
> }
> 
> ```

But I'm getting an error: "No field found for [@timestamp] in mapping with types "

```
        "(doc['@timestamp'].value.toInstant().toEpochMilli() - doc.eventTime.value.toInstant().toEpochMilli()) / 1000",
        " ^---- HERE"

```

My question is how to get this scripted field to work? Either by using painless or expression language. I've tried various approaches but with no luck.  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![rjernst](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rjernst/32/6363_2.png) [@rjernst](https://discuss.elastic.co/u/rjernst)\
**Post date:** [October 5, 2019, 5:08pm UTC](https://discuss.elastic.co/t/calculating-time-diff-between-timestamp-and-document-date-field/201918/2 "2019-10-05T17:08:30Z")

</div>

Do you have a field in your mappings called `@timestamp`? The error indicates there is no mapping for that field. One thing to consider is which indexes your query is on. Given your script, all indexes you are querying would need to have both `@timestamp` and `eventTime` mapped.

---

<div class="post-metadata">

**Author:** ![Josip\_Cagalj](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josip_cagalj/32/42899_2.png) [@Josip\_Cagalj](https://discuss.elastic.co/u/Josip_Cagalj)\
**Post date:** [October 7, 2019, 8:28am UTC](https://discuss.elastic.co/t/calculating-time-diff-between-timestamp-and-document-date-field/201918/3 "2019-10-07T08:28:58Z")

</div>

HI,  
You are right, I don't have mapping for `@timestamp` field. It's special field introduced by Logstash but I would like to have access to its value if possible.  
I can see this field and it's value when in Kibana expanding the `_source` booth in JSON or Table tab:  
 ![1](https://us1.discourse-cdn.com/elastic/original/3X/f/0/f0d6be7c35b685f003ca6058079b69285854f465.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2019, 8:29am UTC](https://discuss.elastic.co/t/calculating-time-diff-between-timestamp-and-document-date-field/201918/4 "2019-11-04T08:29:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
