# Elapsed filter but problem in calculate the real diference

**URL:** <https://discuss.elastic.co/t/elapsed-filter-but-problem-in-calculate-the-real-diference/166760>\
**Category:** Logstash\
**Created:** [February 1, 2019, 4:44pm UTC](https://discuss.elastic.co/t/elapsed-filter-but-problem-in-calculate-the-real-diference/166760 "2019-02-01T16:44:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bigster](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@bigster](https://discuss.elastic.co/u/bigster)\
**Post date:** [February 1, 2019, 4:44pm UTC](https://discuss.elastic.co/t/elapsed-filter-but-problem-in-calculate-the-real-diference/166760/1 "2019-02-01T16:44:22Z")

</div>

Hi all,

I´ve a elapsed filter but the calculation of the elapsed time is based on the timestamp value the occurs when the data enters the Elastic not the value i'm getting from the DB.  
I've seen a couple of posts saying to override the timestamp field but i can't make it work.

Here is my configuration:

> input {  
> jdbc {  
> jdbc\_driver\_library =\> "D:\elk\logstash-6.1.1\vendor\ibm\db2jcc.jar"  
> jdbc\_driver\_class =\> "com.ibm.db2.jcc.DB2Driver"  
> jdbc\_connection\_string =\> "XXXXX"  
> jdbc\_user =\> "XXXX"  
> jdbc\_password =\> "XXXXX"  
> tracking\_column =\> date\_created  
> tracking\_column\_type =\> "timestamp"  
> last\_run\_metadata\_path =\> "D:\elk\logstash-6.1.1\metadata\logstash\_jdbc\_qld\_v2\_last\_run"  
> use\_column\_value =\> true  
> schedule =\> "\* \* \* \* \*"  
> statement =\> "SELECT DATE\_CREATED,  
> DESTINATION\_HOST, OPERATION\_ID, MESSAGE  
> FROM COMMUNICATION\_LOG  
> WHERE DATE\_CREATED \> :sql\_last\_value "  
> }  
> }  
> filter {  
> date {  
> match =\> ["date\_created", "yyyy-MM-dd HH:mm:ss,SSS"]  
> target =\> "@timestamp"  
> }  
> if [message\_type] == "Req" {  
> mutate {  
> add\_tag =\> ["taskStarted"]  
> }  
> }  
> if [message\_type] == "Res" {  
> mutate {  
> add\_tag =\> ["taskTerminated"]  
> }  
> }   
> elapsed {  
> unique\_id\_field =\> "operation\_id"  
> start\_tag =\> "taskStarted"  
> end\_tag =\> "taskTerminated"  
> timeout =\> 30  
> }  
> }  
> output {  
> elasticsearch {  
> hosts =\> ["127.0.0.1:9200"]  
> index =\> "eai\_qua\_log\_v2-%{+YYYY.MM.dd}"  
> document\_id =\>"%{communication\_id}"  
> }  
> }

I'm still getting the diference:

- "@timestamp": "2019-02-01T16:32:00.156Z"
- "date\_created": "2019-02-01T16:30:56.738Z",

And the elapsed time is calculated with the timestamp, so the values are not real.

Can anyone help?

Cheers.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 1, 2019, 7:21pm UTC](https://discuss.elastic.co/t/elapsed-filter-but-problem-in-calculate-the-real-diference/166760/2 "2019-02-01T19:21:55Z")

</div>

> [@bigster](#):
>
> "date\_created": "2019-02-01T16:30:56.738Z"

That does not match "yyyy-MM-dd HH:mm:ss,SSS". Change your date filter to

```
date { match => ["date_created", "ISO8601"] }

```

---

<div class="post-metadata">

**Author:** ![bigster](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@bigster](https://discuss.elastic.co/u/bigster)\
**Post date:** [February 4, 2019, 1:58pm UTC](https://discuss.elastic.co/t/elapsed-filter-but-problem-in-calculate-the-real-diference/166760/3 "2019-02-04T13:58:37Z")

</div>

[quote="bigster, post:1, topic:166760"]  
target =\> "@timestamp"  
[/quote]I've changed the date format, but i still get diferences between the date\_created and the @timestamp.

"@timestamp": "2019-02-04T13:56:00.233Z"  
"date\_created": "2019-02-04T13:55:58.515Z"  
"elapsed\_timestamp\_start": "2019-02-04T13:56:00.233Z"

What i miss?

---

<div class="post-metadata">

**Author:** ![bigster](https://avatars.discourse-cdn.com/v4/letter/b/8e7dd6/32.png) [@bigster](https://discuss.elastic.co/u/bigster)\
**Post date:** [February 6, 2019, 5:50pm UTC](https://discuss.elastic.co/t/elapsed-filter-but-problem-in-calculate-the-real-diference/166760/4 "2019-02-06T17:50:53Z")

</div>

Hi all,

Update for my old comment:  
i get \_dateparsefailure when i put the "ISO8601"

Anyone knows anything to help?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 6, 2019, 5:50pm UTC](https://discuss.elastic.co/t/elapsed-filter-but-problem-in-calculate-the-real-diference/166760/5 "2019-03-06T17:50:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
