# Create new fields in elasticsearch

**URL:** <https://discuss.elastic.co/t/create-new-fields-in-elasticsearch/332659>\
**Category:** Elasticsearch\
**Tags:** painless\
**Created:** [May 5, 2023, 2:44pm UTC](https://discuss.elastic.co/t/create-new-fields-in-elasticsearch/332659 "2023-05-05T14:44:20Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![kibana\_dev\_iko](https://avatars.discourse-cdn.com/v4/letter/k/8797f3/32.png) [@kibana\_dev\_iko](https://discuss.elastic.co/u/kibana_dev_iko)\
**Post date:** [May 5, 2023, 2:44pm UTC](https://discuss.elastic.co/t/create-new-fields-in-elasticsearch/332659/1 "2023-05-05T14:44:20Z")

</div>

i want to calculate the difference in time between 2 logs different and add the value to a new field  
i search in google and i find that is possible with painless scripting but i dont know how to do it  
if there is anyone who already use painless scripting to add new fields can help me  
btw i inject logs with filebeat to elastic saerch

thank you so much

---

<div class="post-metadata">

**Author:** ![eMitch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/emitch/32/93607_2.png) [@eMitch](https://discuss.elastic.co/u/eMitch)\
**Post date:** [May 11, 2023, 7:19pm UTC](https://discuss.elastic.co/t/create-new-fields-in-elasticsearch/332659/2 "2023-05-11T19:19:15Z")

</div>

On its own, using painless to add a field is pretty straightforward. This would be easier to accomplish if the time differences were stored on the same document. Here's an example \_update\_by\_query painless script of that scenario:

```auto
POST log_duration_testing/_update_by_query
{
  "query": {
    "match_all": {}
  },
  "script": {
    "lang": "painless",
    "source": """
      ZonedDateTime zdt_start = ZonedDateTime.parse(ctx._source['event_start_datetime']);
      ZonedDateTime zdt_stop = ZonedDateTime.parse(ctx._source.event_stop_datetime);
      long event_start_datetime_millis = zdt_start.toInstant().toEpochMilli();
      long event_stop_datetime_millis = zdt_stop.toInstant().toEpochMilli();
      long durationMillis = event_stop_datetime_millis - event_start_datetime_millis;
      ctx._source.duration_sec = durationMillis / 1000;
    """
  }
}

```

When run, this would update all documents in the `log_duration_testing` index and add a field called `duration_sec` based on the difference between the fields `event_stop_datetime` and `event_start_datetime`.

However, if you're looking to compare the differences in time between separate documents, that becomes a different tactic.

One way to accomplish this would be to do something similar to what is discussed [here with transforms.](https://xeraa.net/blog/2021_elasticsearch-transforms-duration-status-updates/)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 8, 2023, 7:19pm UTC](https://discuss.elastic.co/t/create-new-fields-in-elasticsearch/332659/3 "2023-06-08T19:19:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
