# Convert Number (elapsed\_time) into Time (HH:MM:SS)

**URL:** <https://discuss.elastic.co/t/convert-number-elapsed-time-into-time-hhss/218551>\
**Category:** Logstash\
**Created:** [February 10, 2020, 9:32am UTC](https://discuss.elastic.co/t/convert-number-elapsed-time-into-time-hhss/218551 "2020-02-10T09:32:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Thibaut\_M](https://avatars.discourse-cdn.com/v4/letter/t/d6d6ee/32.png) [@Thibaut\_M](https://discuss.elastic.co/u/Thibaut_M)\
**Post date:** [February 10, 2020, 9:32am UTC](https://discuss.elastic.co/t/convert-number-elapsed-time-into-time-hhss/218551/1 "2020-02-10T09:32:52Z")

</div>

Hello,

Let me expose what i'm trying to achieve here. I calculate an elapsed\_time (with the elapsed plugin) between two documents. elapsed\_time is in second and i want it like this : HH:MM:SS so as an example : 80 sec = 00:01:20 but i'm struggling to do this. At first, I tried in kibana with Scripted fields and follow the response of LeeDr in this link : [JSON Input: Converting Minutes to Minutes and Seconds](https://discuss.elastic.co/t/json-input-converting-minutes-to-minutes-and-seconds/100845)

But i got this error :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/d/0/d07ca91e460bad456aeb5fe5ea9c76420bf0a58f.png)

And I have document :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/9/299ad9abac08ff892cd8c72f20023d5faa385671.png)

My elapsed\_time fields is a number (like LeeDr response)

I tried then something else with the ruby filter without success...

This is my elapsed filter :

> ```
> if [virtual_ip] == "IP adress" {
> elapsed {
> unique_id_field => "username"
> start_tag => "Connection started"
> end_tag => "Connection terminated"
> timeout => 86400
> add_tag => ["time_elapsed"]
> }
> } else {
> elapsed {
> unique_id_field => "username"
> start_tag => "Connection started"
> end_tag => "Connection terminated"
> timeout => 86400
> add_tag => ["time_elapsed_bis"]
> }
> }
> ruby {
> code => "event.set('duration_time', (event.get('elapsed_time').Time.utc.strftime('%H:%M:%S'))) rescue nil"
> 
> ```
> 
> }

This ruby code doesn't work, I don't see any value in kibana for the field "duration\_time"

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/6/9617f87df7713a96628f684bba6101accba1ad0e.png)

I tried everything in the ruby code : just strftime('%H:%M:%S'), without "utc" but same result at the end.

Moreover I tried this

> code =\> "event.set('duration\_time', (event.get('@timestamp') - event.get('elapsed\_timestamp\_start')) / 60) rescue nil"

I get "duration\_time" in minute but 2 minutes 30 secondes will be displayed as follow : 2.5 and this is not what i want

Could you please guys help me on this ? I don't know what else to try or if i'm doing something wrong

Thank you for your help  
Thibaut

---

<div class="post-metadata">

**Author:** ![Thibaut\_M](https://avatars.discourse-cdn.com/v4/letter/t/d6d6ee/32.png) [@Thibaut\_M](https://discuss.elastic.co/u/Thibaut_M)\
**Post date:** [February 20, 2020, 7:10am UTC](https://discuss.elastic.co/t/convert-number-elapsed-time-into-time-hhss/218551/2 "2020-02-20T07:10:40Z")

</div>

Anyone ?

---

<div class="post-metadata">

**Author:** ![angelo](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/angelo/32/61325_2.png) [@angelo](https://discuss.elastic.co/u/angelo)\
**Post date:** [March 13, 2020, 3:55pm UTC](https://discuss.elastic.co/t/convert-number-elapsed-time-into-time-hhss/218551/3 "2020-03-13T15:55:15Z")

</div>

In terms of Kibana and the error that you have in your screenshot, it's pointing out that you have some documents that have a missing value for `elapsed_time` and that you should do a check first. So with that and assuming that you want to allow hours to be larger than 24 (or else in a date/time format, that would increment the day field), here is an example:

```auto
if (doc['elapsed_time'].size()==0) {
    return ""
} else {
    long elapsed_time=(long)doc["elapsed_time"].value*1000;

    long secondsInMilli = 1000;
    long minutesInMilli = secondsInMilli * 60;
    long hoursInMilli = minutesInMilli * 60;
    long daysInMilli = hoursInMilli * 24;

    // long elapsedDays = elapsed_time / daysInMilli;
    // elapsed_time = elapsed_time % daysInMilli;/
	
    long elapsedHours = elapsed_time / hoursInMilli;
    elapsed_time = elapsed_time % hoursInMilli;

    long elapsedMinutes = elapsed_time / minutesInMilli;
    elapsed_time = elapsed_time % minutesInMilli;

    long elapsedSeconds = elapsed_time / secondsInMilli;

    String my_answer = String.format('%02d:%02d:%02d', new def[] {(int)elapsedHours, (int)elapsedMinutes, (int)elapsedSeconds});
    return my_answer;
}

```

I left `elapsedDays` as a comment just in case you did want to use it.

 ![elapsed_time_scipted_field](https://us1.discourse-cdn.com/elastic/original/3X/6/8/682a51fcff8247b0026f97e643dfb7e89eb78fb3.png)

---

<div class="post-metadata">

**Author:** ![Thibaut\_M](https://avatars.discourse-cdn.com/v4/letter/t/d6d6ee/32.png) [@Thibaut\_M](https://discuss.elastic.co/u/Thibaut_M)\
**Post date:** [March 18, 2020, 11:42am UTC](https://discuss.elastic.co/t/convert-number-elapsed-time-into-time-hhss/218551/4 "2020-03-18T11:42:29Z")

</div>

Hi Angelo,

Thank you for your answer.

I try to do what you said. I see that it is working in the preview

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/8/a/8a03a5077a85d3826dd12e382b0b185e4f0d5c6a.png)

But it is not working. I get 0 value

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/4/748ad6ae44850bd0fe801abe8e43490e82b18268.png)

Have I doing something wrong ? Is there an another option ?

Thank you for helping me  
Thibaut

---

<div class="post-metadata">

**Author:** ![Thibaut\_M](https://avatars.discourse-cdn.com/v4/letter/t/d6d6ee/32.png) [@Thibaut\_M](https://discuss.elastic.co/u/Thibaut_M)\
**Post date:** [March 18, 2020, 12:58pm UTC](https://discuss.elastic.co/t/convert-number-elapsed-time-into-time-hhss/218551/5 "2020-03-18T12:58:34Z")

</div>

I found a solution by doing this

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/6/c6f9696075dccf77c62dc2ffe081d7a009d4251d.png)

It displayed the time how i want but the field is in a date format, so i cannot use this to do an average or max vizualisation since it's not a number.

Angelo, in your script if i only let

> if (doc['elapsed\_time'].size()==0) {  
> return ""  
> } else {  
> doc["elapsed\_time"].value\*1000;  
> }

and keep this as a Number and not a date

I have my value multiply by 1000 (seems logic) but when i try to add the next piece of script that you gave, I have the 0 value that I show presviously

Thibaut

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 15, 2020, 12:58pm UTC](https://discuss.elastic.co/t/convert-number-elapsed-time-into-time-hhss/218551/6 "2020-04-15T12:58:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
