# Convert Microseconds to Milliseconds

**URL:** <https://discuss.elastic.co/t/convert-microseconds-to-milliseconds/169453>\
**Category:** Logstash\
**Created:** [February 21, 2019, 3:46pm UTC](https://discuss.elastic.co/t/convert-microseconds-to-milliseconds/169453 "2019-02-21T15:46:04Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jwilson-chess](https://avatars.discourse-cdn.com/v4/letter/j/df788c/32.png) [@jwilson-chess](https://discuss.elastic.co/u/jwilson-chess)\
**Post date:** [February 21, 2019, 3:46pm UTC](https://discuss.elastic.co/t/convert-microseconds-to-milliseconds/169453/1 "2019-02-21T15:46:04Z")

</div>

I have the following ruby code to do a conversion:

```
ruby {
    code => "event.set('redis.slowlog.duration.ms', event.get('redis.slowlog.duration.us').to_f / 1000)"
}

```

But it doesn't seem to produce any output:

 ![57%20AM](https://us1.discourse-cdn.com/elastic/original/3X/c/e/cefd539762d18d30e64564e881f4373e9e63321f.png)

I've tried adding an exception handler but it doesn't produce anything either. The data is being sent via filebeat using the redis slowlog prospector.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 21, 2019, 4:01pm UTC](https://discuss.elastic.co/t/convert-microseconds-to-milliseconds/169453/2 "2019-02-21T16:01:17Z")

</div>

It works for me

```
"redis.slowlog.duration.us" => "12613",
"redis.slowlog.duration.ms" => 12.613
```

---

<div class="post-metadata">

**Author:** ![jwilson-chess](https://avatars.discourse-cdn.com/v4/letter/j/df788c/32.png) [@jwilson-chess](https://discuss.elastic.co/u/jwilson-chess)\
**Post date:** [February 21, 2019, 4:14pm UTC](https://discuss.elastic.co/t/convert-microseconds-to-milliseconds/169453/3 "2019-02-21T16:14:38Z")

</div>

Yes, everything says it should work but it isn't.

Here's the full logstash config:

```
input {
    beats {
        port => 5045
        host => "0.0.0.0"
    }
}

filter {
    if [fields][data_type] == "redis-slowlog" {
        date {
            match => ["timestamp", "UNIX"]
        }

        mutate {
            remove_field => ["headers","fields","type"]
            rename => ["host", "server"]
            convert => {"server" => "string"}
        }

        ruby {
            code => "begin
                        event.set('redis.slowlog.duration.ms', event.get('redis.slowlog.duration.us').to_f / 1000)
                        rescue Exception => e
                        event['ruby_exception'] = 'Exception:' + e.message
                     end"
        }

        if "_grokparsefailure" not in [tags] {
            mutate {
                remove_field => ["message"]
            }
        }
    }
}

output {
    if "redis-slowlog" in [tags] {
        elasticsearch {
            hosts => "localhost:9200"
            index => "redis-slowlog-%{+YYYY.MM.dd}"
        }
    }
}

```

And the filebeat config:

```
filebeat.modules:
- module: redis

filebeat.prospectors:
- type: redis
  hosts: ["localhost:6379"]
  fields:
    data_type: redis-slowlog

tags: ["redis-slowlog"]

output.logstash:
  hosts: ["10.0.0.76:5045"]
```

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [February 21, 2019, 5:05pm UTC](https://discuss.elastic.co/t/convert-microseconds-to-milliseconds/169453/4 "2019-02-21T17:05:57Z")

</div>

You could install the `logstash-filter-math` filter [(docs)](https://www.elastic.co/guide/en/logstash-versioned-plugins/current/v1.1.1-plugins-filters-math.html).  
You will need to convert any string based numbers to integers or floats first though.  
Example:

```auto
    math {
      calculate => [
        ["fdiv", "[millimeters_f]", 25.4, "[inches]"]
      ]
    }

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 21, 2019, 5:06pm UTC](https://discuss.elastic.co/t/convert-microseconds-to-milliseconds/169453/5 "2019-03-21T17:06:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
