# Elapsed filter and logstash 1.5

**URL:** <https://discuss.elastic.co/t/elapsed-filter-and-logstash-1-5/2232>\
**Category:** Logstash\
**Created:** [June 9, 2015, 4:09pm UTC](https://discuss.elastic.co/t/elapsed-filter-and-logstash-1-5/2232 "2015-06-09T16:09:21Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![sanaya](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@sanaya](https://discuss.elastic.co/u/sanaya)\
**Post date:** [June 9, 2015, 4:09pm UTC](https://discuss.elastic.co/t/elapsed-filter-and-logstash-1-5/2232/1 "2015-06-09T16:09:21Z")

</div>

Hello,

I'm just getting started with logstash, and I have been using the elapsed filter on version 1.4.2.  
However, upgrading to version 1.5 the elapsed filter doesn't seem to generate an expired event any more. Is there a new configuration for the filter I'm not seeing or is this a bug?

I'm running on a windows platform.

Thanks

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 10, 2015, 3:17am UTC](https://discuss.elastic.co/t/elapsed-filter-and-logstash-1-5/2232/2 "2015-06-10T03:17:36Z")

</div>

Can you provide your config?

---

<div class="post-metadata">

**Author:** ![sanaya](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@sanaya](https://discuss.elastic.co/u/sanaya)\
**Post date:** [June 10, 2015, 4:02pm UTC](https://discuss.elastic.co/t/elapsed-filter-and-logstash-1-5/2232/3 "2015-06-10T16:02:28Z")

</div>

```auto
input {
  file {
         path => "C:/temp/combined.txt"
         type => "TG"
		 start_position => "beginning"
		 sincedb_path => "C:/temp/combined_sincedb"
       }
 }

filter {
    if [type] == "TG" {
	  
      grok {
         match => ["message", "\[%{TIMESTAMP_ISO8601:LogTimestamp}\] %{WORD:Status}-%{GREEDYDATA:RepId}, %{GREEDYDATA:Test}, Session:%{GREEDYDATA:Session}, package id: %{UUID:ClientPackageIdentifier}, %{TIMESTAMP_ISO8601:SentAt}, (?<ClientIdentifier>\S*)",
		                 "message", "\[%{TIMESTAMP_ISO8601:LogTimestamp}\] %{WORD:Status}-%{GREEDYDATA:RepId}, Session:%{GREEDYDATA:Session}, package id: %{UUID:ClientPackageIdentifier}, %{TIMESTAMP_ISO8601:ReceivedAt}, Sequence:%{NUMBER:Sequence}, RequestRetries:%{NUMBER:RequestRetries}, ResponseRetries:%{NUMBER:ResponseRetries}, %{WORD:ResponseReason}, %{WORD:ErrorCode}, Occured at: %{TIMESTAMP_ISO8601:OccuredAt}, SSI:%{POSINT:SSI}, ClientId: (?<ClientIdentifier>\S*)"
		 ]
		 
		 add_tag => ["%{ClientIdentifier}"]
		 add_tag => ["%{Status}"]
      }	
	  
      date {
	           match => ["LogTimestamp", "YYYY-MM-dd HH:mm:ss.SSS"]
       }

	if "_grokparsefailure" in [tags] {
      drop { }
    }	
 }
 
	elapsed {
	   start_tag => "Sending"
	   end_tag => "Response"
	   unique_id_field => "ClientPackageIdentifier"
	   timeout => 60
	   new_event_on_match => false
	}
}

 output {
    elasticsearch { 
	   host => "localhost"
	   index => "test"
	   protocol => "http"
	   }
    file {
        path => "c:\temp\result.txt"
		flush_interval => 0
	}
	
}
```

The status field is either Sending or Response which is my start and stop tag.

Thanks!

---

<div class="post-metadata">

**Author:** ![sanaya](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@sanaya](https://discuss.elastic.co/u/sanaya)\
**Post date:** [July 2, 2015, 9:52pm UTC](https://discuss.elastic.co/t/elapsed-filter-and-logstash-1-5/2232/4 "2015-07-02T21:52:51Z")

</div>

Any followup on this?

I tried with the latest 1.5.2 version of Logstash, and still don't get an elapsed.expired\_error event.

Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:35am UTC](https://discuss.elastic.co/t/elapsed-filter-and-logstash-1-5/2232/5 "2017-07-06T05:35:42Z")

</div>


