# Comparing date/time from two different documents

**URL:** <https://discuss.elastic.co/t/comparing-date-time-from-two-different-documents/130933>\
**Category:** Kibana\
**Created:** [May 8, 2018, 5:33am UTC](https://discuss.elastic.co/t/comparing-date-time-from-two-different-documents/130933 "2018-05-08T05:33:55Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![uhaslund](https://avatars.discourse-cdn.com/v4/letter/u/9fc348/32.png) [@uhaslund](https://discuss.elastic.co/u/uhaslund)\
**Post date:** [May 8, 2018, 5:33am UTC](https://discuss.elastic.co/t/comparing-date-time-from-two-different-documents/130933/1 "2018-05-08T05:33:55Z")

</div>

Hi,

The scenario is this:

1. Same index
2. Two different documents A and B
3. Document A contains a log entry for event "Client Requests X"
4. Document B contains a log entry for event "Client Request Accepted"

How do I calculate the time difference between these two timestamps, and ideally how do I visualize this?

Thanks!

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 8, 2018, 6:38am UTC](https://discuss.elastic.co/t/comparing-date-time-from-two-different-documents/130933/2 "2018-05-08T06:38:11Z")

</div>

Kibana cannot currently do that sorry.

You'd need to add that to the second document during ingest.

---

<div class="post-metadata">

**Author:** ![uhaslund](https://avatars.discourse-cdn.com/v4/letter/u/9fc348/32.png) [@uhaslund](https://discuss.elastic.co/u/uhaslund)\
**Post date:** [May 8, 2018, 6:44am UTC](https://discuss.elastic.co/t/comparing-date-time-from-two-different-documents/130933/3 "2018-05-08T06:44:42Z")

</div>

How about comparing two timestamps aggregated over a specific term or field?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 8, 2018, 6:45am UTC](https://discuss.elastic.co/t/comparing-date-time-from-two-different-documents/130933/4 "2018-05-08T06:45:40Z")

</div>

You can do it if it's in the same document, but not between documents. That currently needs to be done outside of the stack, in your own client for eg.

---

<div class="post-metadata">

**Author:** ![uhaslund](https://avatars.discourse-cdn.com/v4/letter/u/9fc348/32.png) [@uhaslund](https://discuss.elastic.co/u/uhaslund)\
**Post date:** [May 8, 2018, 6:49am UTC](https://discuss.elastic.co/t/comparing-date-time-from-two-different-documents/130933/5 "2018-05-08T06:49:26Z")

</div>

Ok, that basically rules out any time comparison in our setup where independent services on the network are logging to their individual log files and they are being sourced via Logstash into Elastic. I thought that was the whole idea with the Elastic Stack...or am I missing something? 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 8, 2018, 6:51am UTC](https://discuss.elastic.co/t/comparing-date-time-from-two-different-documents/130933/6 "2018-05-08T06:51:01Z")

</div>

Are you looking to find discrepancies in response times?

---

<div class="post-metadata">

**Author:** ![uhaslund](https://avatars.discourse-cdn.com/v4/letter/u/9fc348/32.png) [@uhaslund](https://discuss.elastic.co/u/uhaslund)\
**Post date:** [May 8, 2018, 6:53am UTC](https://discuss.elastic.co/t/comparing-date-time-from-two-different-documents/130933/7 "2018-05-08T06:53:45Z")

</div>

Well, yes...sort of...I want to visualize the latency trend of a given business operation, and that latency is the delta between start of operation A on server A and end of operation B on server B. Both servers A and B's log files are in the same index, but obviously as two separate documents. They do, however, correlate via a unique transaction id which is an indexed field in both documents.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 8, 2018, 6:58am UTC](https://discuss.elastic.co/t/comparing-date-time-from-two-different-documents/130933/8 "2018-05-08T06:58:23Z")

</div>

Yeah ok. There's no algorithm in Elasticsearch to calculate this, and Kibana doesn't have anything at this stage. If it were in the same event, eg start + end time, then you can add it with a scripted field.

Generally though it would be stored as a value in the event, eg as captured by Packetbeat or as calculated by Logstash.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 8, 2018, 7:02am UTC](https://discuss.elastic.co/t/comparing-date-time-from-two-different-documents/130933/9 "2018-05-08T07:02:52Z")

</div>

For this type of analysis, you may want to consider [entity-centric indexing](https://www.youtube.com/watch?v=yBf7oeJKH2Y).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 5, 2018, 7:03am UTC](https://discuss.elastic.co/t/comparing-date-time-from-two-different-documents/130933/10 "2018-06-05T07:03:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
