# Converting elapsed time 00:00:00:XXXXXXX

**URL:** <https://discuss.elastic.co/t/converting-elapsed-time-00-00-00-xxxxxxx/74237>\
**Category:** Logstash\
**Created:** [February 7, 2017, 3:13pm UTC](https://discuss.elastic.co/t/converting-elapsed-time-00-00-00-xxxxxxx/74237 "2017-02-07T15:13:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dsever](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dsever](https://discuss.elastic.co/u/dsever)\
**Post date:** [February 7, 2017, 3:13pm UTC](https://discuss.elastic.co/t/converting-elapsed-time-00-00-00-xxxxxxx/74237/1 "2017-02-07T15:13:28Z")

</div>

Hi there,

I have small problem with small problem with preparing elapsed time for executing db procedure.  
For instance using grok as %{TIME:elapsed} and it matches ok, but at eleastic it provides me value as string.  
for example:  
"elapsed"=\> "00:00:00.0029343" and it is represented like string, and I'm trying to have it in date format  
like 00:00:00:XXXXXXX.

Probably it is possible using mutate filter, but I'm not sure how can I use it with date formats.

Any instruction would be useful

EDIT: resolved by using template, and converted to format 1970-01-01 HH:mm:ss.SSSSSSS

Thanks  
Dubravko

---

<div class="post-metadata">

**Author:** ![fbaligand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fbaligand/32/5657_2.png) [@fbaligand](https://discuss.elastic.co/u/fbaligand)\
**Post date:** [February 8, 2017, 2:05pm UTC](https://discuss.elastic.co/t/converting-elapsed-time-00-00-00-xxxxxxx/74237/2 "2017-02-08T14:05:28Z")

</div>

Another way to do that (compared to elasticsearch template), is to use Logstash "date" filter.

That said, I'm surprised that you try to convert a duration to a timestamp.

---

<div class="post-metadata">

**Author:** ![dsever](https://avatars.discourse-cdn.com/v4/letter/d/91b2a8/32.png) [@dsever](https://discuss.elastic.co/u/dsever)\
**Post date:** [February 9, 2017, 8:20am UTC](https://discuss.elastic.co/t/converting-elapsed-time-00-00-00-xxxxxxx/74237/3 "2017-02-09T08:20:56Z")

</div>

I've already tried by using date, in that case:  
target =\> fields will extend it with "date xx:xx:xx.SSSSSSS" where date is today (just to be sure I will try ones again)

So decide to fixed it to unix time.

Dubravko

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 9, 2017, 8:21am UTC](https://discuss.elastic.co/t/converting-elapsed-time-00-00-00-xxxxxxx/74237/4 "2017-03-09T08:21:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
