# Combining two events in one to calculate time difference

**URL:** https://discuss.elastic.co/t/combining-two-events-in-one-to-calculate-time-difference/292155
**Category:** Logstash
**Created:** [December 16, 2021, 1:00pm UTC](https://discuss.elastic.co/t/combining-two-events-in-one-to-calculate-time-difference/292155 "2021-12-16T13:00:02Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![mangeshmj1992](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)
#### Post date: [December 16, 2021, 1:00pm UTC](https://discuss.elastic.co/t/combining-two-events-in-one-to-calculate-time-difference/292155/1 "2021-12-16T13:00:02Z")

</div>

Hello team,  
I have case where information is being displayed in different lines. These lines are not even consecutive lines. Unique field is log\_processed.companyId. I have to display time difference between entry and exit log.

I have tried with aggregate filter but it didn't work

Sample log:

```auto
{"timestamp":"2021-11-17T05:52:59:613","level":"info","message":"ENTRY: INTERNAL_HTTP_REQUEST","userId":"rahul","companyId":"abc"}

{"timestamp":"2021-11-17T05:52:59:768","level":"info","message":"EXIT: INTERNAL_HTTP_REQUEST","userId":"rahul","companyId":"abc"}

```

Aggregate filter:

```auto
if [log_processed.message] == "ENTRY: INTERNAL_HTTP_REQUEST" {
        aggregate {
            task_id => "%{log_processed.companyId}"
            code => "map['started'] = event['@timestamp']"
            map_action => "create"
        }
    }

    if [log_processed.message] == "EXIT: INTERNAL_HTTP_REQUEST" {
        aggregate {
            task_id => "%{log_processed.companyId}"
            code => "event['duration'] = event['@timestamp'] - map['started']"
            map_action => "update"
            push_map_as_event_on_timeout => true
            timeout_task_id_field => "log_processed.companyId"
            timeout => 60 # 1 minutes timeout
			timeout_tags => ['_aggregatetimeout']
        }
    }

```

---

<div class="post-metadata">

### Author: ![mangeshmj1992](https://avatars.discourse-cdn.com/v4/letter/m/d9b06d/32.png) [@mangeshmj1992](https://discuss.elastic.co/u/mangeshmj1992)
#### Post date: [December 16, 2021, 3:00pm UTC](https://discuss.elastic.co/t/combining-two-events-in-one-to-calculate-time-difference/292155/2 "2021-12-16T15:00:07Z")

</div>

Hello @Badger ,  
Can you please help me here

---

<div class="post-metadata">

### Author: ![stevedearl](https://avatars.discourse-cdn.com/v4/letter/s/48db29/32.png) [@stevedearl](https://discuss.elastic.co/u/stevedearl)
#### Post date: [December 16, 2021, 3:35pm UTC](https://discuss.elastic.co/t/combining-two-events-in-one-to-calculate-time-difference/292155/3 "2021-12-16T15:35:54Z")

</div>

Hi @mangeshmj1992 ,

You should take a look at the Elapsed Filter as from your description that does what you're looking for.

We have 'start' and 'end' events (separate documents being fed by Logstash into Elasticsearch). They both contain a unique ID so it's possible to correlate which 'end' event relates to which 'start' event.  
The elapsed plugin can monitor for these events, correlate them together and provide the 'elapsed time' by subtracting the start event timestamp from the end event timestamp.

Note that it's critical to have a unique correlation ID that both events contain.

Hope that helps,  
Steve

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 13, 2022, 3:36pm UTC](https://discuss.elastic.co/t/combining-two-events-in-one-to-calculate-time-difference/292155/4 "2022-01-13T15:36:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
