# Calculation in mutate field

**URL:** <https://discuss.elastic.co/t/calculation-in-mutate-field/2703>\
**Category:** Logstash\
**Created:** [June 15, 2015, 2:29pm UTC](https://discuss.elastic.co/t/calculation-in-mutate-field/2703 "2015-06-15T14:29:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ankit\_Pradhan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ankit_pradhan/32/44412_2.png) [@Ankit\_Pradhan](https://discuss.elastic.co/u/Ankit_Pradhan)\
**Post date:** [June 15, 2015, 2:29pm UTC](https://discuss.elastic.co/t/calculation-in-mutate-field/2703/1 "2015-06-15T14:29:11Z")

</div>

I have filed TIME field and I would like to convert HHmmss to only Seconds.

e.g.  
"duration": [  
[  
"0:00:00"  
]  
],  
"HOUR": [  
[  
"0"  
]  
],  
"MINUTE": [  
[  
"00"  
]  
],  
"SECOND": [  
[  
"00"  
]  
]

I would like to have a new field in which I can convert the duration to only Seconds with the formula (like [HOUR_60_60 + MINUTE\*60 + SECOND] )

I tried  
grok {  
match =\> ["eventDescription", "%{SPACE}:%{SPACE}%{WORD}%{SPACE}%{WORD}%{SPACE}%{WORD}%{SPACE}%{WORD}%{SPACE}%{SPACE}%{TIME:duration}"]  
}  
#mutate { add\_field =\> {"xfbTransferDuration" =\> [HOUR_60_60 + MINUTE\*60 + SECOND] }}

But this does not work.

What is the possible to way to get the TIME in Seconds.

Input String: : CFTU20I Session active for 0:00:00  
Grok: %{SPACE}:%{SPACE}%{WORD}%{SPACE}%{WORD}%{SPACE}%{WORD}%{SPACE}%{WORD}%{SPACE}%{SPACE}%{TIME:duration}

---

<div class="post-metadata">

**Author:** ![eperry](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/eperry/32/551_2.png) [@eperry](https://discuss.elastic.co/u/eperry)\
**Post date:** [June 17, 2015, 7:19am UTC](https://discuss.elastic.co/t/calculation-in-mutate-field/2703/2 "2015-06-17T07:19:38Z")

</div>

I think the solition for what you want to do is the ruby filter, but I don't have much experience in using it.

I find that the mutate filter is limited and every solution about "caculations' say to go to the ruby.

---

<div class="post-metadata">

**Author:** ![chaitanyavvs](https://avatars.discourse-cdn.com/v4/letter/c/46a35a/32.png) [@chaitanyavvs](https://discuss.elastic.co/u/chaitanyavvs)\
**Post date:** [June 17, 2015, 2:25pm UTC](https://discuss.elastic.co/t/calculation-in-mutate-field/2703/3 "2015-06-17T14:25:09Z")

</div>

Hi,  
Source : [https://groups.google.com/forum/#!topic/logstash-users/iEYRv7bCqdM](https://groups.google.com/forum/#!topic/logstash-users/iEYRv7bCqdM)

I have searched the google groups of logstash and found a post asking almost the same kind of functionality. The proposed solution is as below

```
filter {    
     if [sendout_count] and [transport_time] {
        ruby {            
              code => "event['per_sendout_transport_time'] = event['transport_time'] / event['sendout_count']"      
           }    
      }
}

```

In your example, i think , you can approach this as follows

```
filter {    
         if [HOUR] and [MINUTE] and [SECOND] {
            ruby {            
                  code => "event['timeInSeconds'] = event['HOUR']*3600+event['MINUTE']*60+event['SECOND']"      
               }    
          }
    }

```

That way, you can get a field named \> timeInSeconds. Hope this helps

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:37am UTC](https://discuss.elastic.co/t/calculation-in-mutate-field/2703/4 "2017-07-06T05:37:13Z")

</div>


