# Compute duration between two ISO8601 fields in the same event

**URL:** <https://discuss.elastic.co/t/compute-duration-between-two-iso8601-fields-in-the-same-event/87497>\
**Category:** Logstash\
**Created:** [May 29, 2017, 11:22pm UTC](https://discuss.elastic.co/t/compute-duration-between-two-iso8601-fields-in-the-same-event/87497 "2017-05-29T23:22:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Myles](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@Myles](https://discuss.elastic.co/u/Myles)\
**Post date:** [May 29, 2017, 11:22pm UTC](https://discuss.elastic.co/t/compute-duration-between-two-iso8601-fields-in-the-same-event/87497/1 "2017-05-29T23:22:22Z")

</div>

I have an oracle ETL table that I am polling with the JDBC input and wanted to add a field as a calculation between the start and end time of the event which is logged in the same event.

Here is what I've tried:

```auto
filter {
	if [type] == "etl" {
		mutate {
			id => "add_etl_index"
			add_field => { "[@metadata][index]" => "active-etl" }
		}
		date {
			id => "parse_etl_last_dttm"
			match => ["last_dttm", "ISO8601"]
		}
		date {
			id => "parse_etl_end_date"
			match => ["end_date", "ISO8601"]
			target => "end_date"
		}
		ruby {
			id => "add_etl_duration"
			code => "event.set('[duration]', event.get('[end_date]') - event.get('[last_dttm]'))"
		}
	}
}

```

But this produces the following Logstash error per event ingested:

```auto
[ERROR][logstash.filters.ruby] Ruby exception occurred: no implicit conversion to rational from string

```

The event is still pushed to elasticsearch but without the desired "duration" field. Any help is most apprecieated.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 30, 2017, 5:15am UTC](https://discuss.elastic.co/t/compute-duration-between-two-iso8601-fields-in-the-same-event/87497/2 "2017-05-30T05:15:07Z")

</div>

`last_dttm` is still a string. You're missing `target => "last_dttm"` in your first date filter.

---

<div class="post-metadata">

**Author:** ![Myles](https://avatars.discourse-cdn.com/v4/letter/m/779978/32.png) [@Myles](https://discuss.elastic.co/u/Myles)\
**Post date:** [May 30, 2017, 12:46pm UTC](https://discuss.elastic.co/t/compute-duration-between-two-iso8601-fields-in-the-same-event/87497/3 "2017-05-30T12:46:35Z")

</div>

Thanks @magnusbaeck. I had actually noticed that but my last\_dttm was still getting indexed as a date type so I didn't think that was the cause but now I see thats only because I set it to the date type in the index template.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 27, 2017, 12:46pm UTC](https://discuss.elastic.co/t/compute-duration-between-two-iso8601-fields-in-the-same-event/87497/4 "2017-06-27T12:46:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
