# Elapsed filter ends in "elapsed\_end\_without\_start"

**URL:** https://discuss.elastic.co/t/elapsed-filter-ends-in-elapsed-end-without-start/183874
**Category:** Logstash
**Created:** [June 3, 2019, 12:56am UTC](https://discuss.elastic.co/t/elapsed-filter-ends-in-elapsed-end-without-start/183874 "2019-06-03T00:56:25Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![ajayraghuraj](https://avatars.discourse-cdn.com/v4/letter/a/e68b1a/32.png) [@ajayraghuraj](https://discuss.elastic.co/u/ajayraghuraj)
#### Post date: [June 3, 2019, 12:56am UTC](https://discuss.elastic.co/t/elapsed-filter-ends-in-elapsed-end-without-start/183874/1 "2019-06-03T00:56:26Z")

</div>

elapsed filter ends in "elapsed\_end\_without\_start". I am running on a VM with 1 vCPU . How do I get over this problem ?  
cpu cores : 1

# /usr/share/logstash/bin/logstash --path.settings /etc/logstash --path.config /etc/logstash/conf.d/test3

{  
"sequence" =\> 0,  
"system" =\> {  
"syslog" =\> {  
"hostname" =\> "ROUTERNAME",  
"program" =\> "51333",  
"message" =\> "May 27 16:19:03.071: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel104, changed state to down",  
"timestamp" =\> "May 28 00:19:03"  
}  
},  
"@timestamp" =\> 2019-05-27T16:19:03.000Z,  
"syslog\_timestamp" =\> "May 27 16:19:03.071",  
"@version" =\> "1",  
"fingerprint" =\> 1590068521,  
"host" =\> "centos6\_vm\_4",  
"messageID" =\> "51333-1590068521",  
"syslog\_message" =\> "%LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel104, changed state to down",  
"message" =\> "May 28 00:19:03 ROUTERNAME 51333: May 27 16:19:03.071: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel104, changed state to down",  
"tags" =\> [  
[0] "tunDOWN"  
]  
}  
{  
"sequence" =\> 0,  
"system" =\> {  
"syslog" =\> {  
"hostname" =\> "ROUTERNAME",  
"program" =\> "51340",  
"message" =\> "May 27 16:19:33.075: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel104, changed state to up",  
"timestamp" =\> "May 28 00:19:33"  
}  
},  
"@timestamp" =\> 2019-05-27T16:19:33.000Z,  
"syslog\_timestamp" =\> "May 27 16:19:33.075",  
"@version" =\> "1",  
"fingerprint" =\> 2154331236,  
"host" =\> "centos6\_vm\_4",  
"messageID" =\> "51340-2154331236",  
"syslog\_message" =\> "%LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel104, changed state to up",  
"message" =\> "May 28 00:19:33 ROUTERNAME 51340: May 27 16:19:33.075: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel104, changed state to up",  
"tags" =\> [  
[0] "tunUP",  
[1] "elapsed\_end\_without\_start"  
]  
}

---

<div class="post-metadata">

### Author: ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)
#### Post date: [June 3, 2019, 6:32am UTC](https://discuss.elastic.co/t/elapsed-filter-ends-in-elapsed-end-without-start/183874/2 "2019-06-03T06:32:23Z")

</div>

> [@ajayraghuraj](#):
>
> elapsed\_end\_without\_star

Have a look on this post: [Problem with elapsed plugin - #3 by pantheo](https://discuss.elastic.co/t/problem-with-elapsed-plugin/52689/3)  
Can you add your configuration file?

---

<div class="post-metadata">

### Author: ![ajayraghuraj](https://avatars.discourse-cdn.com/v4/letter/a/e68b1a/32.png) [@ajayraghuraj](https://discuss.elastic.co/u/ajayraghuraj)
#### Post date: [June 3, 2019, 9:45am UTC](https://discuss.elastic.co/t/elapsed-filter-ends-in-elapsed-end-without-start/183874/3 "2019-06-03T09:45:22Z")

</div>

## here is the configuration file

input {  
generator {  
lines =\> ['May 28 00:19:03 ROUTERNAME 51333: May 27 16:19:03.071: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel104, changed state to down',  
'May 28 00:19:33 ROUTERNAME 51340: May 27 16:19:33.075: %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel104, changed state to up']  
count =\> 1  
}  
}

filter {

grok {  
match =\> { "message" =\> ["%{SYSLOGTIMESTAMP:[system][syslog][timestamp]} %{SYSLOGHOST:[system][syslog][hostname]} %{DATA:[system][syslog][program]}(?:[%{POSINT:[system][syslog][pid]}])?: %{GREEDYDATA:[system][syslog][message]}"] }  
}

date {  
match =\> ["[system][syslog][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]  
}

# Compute Unique message ID

fingerprint {  
source =\> "[system][syslog][message]"  
method =\> "MURMUR3"  
}  
mutate { add\_field =\> { "messageID" =\> "%{[system][syslog][program]}-%{fingerprint}" } }

# Get start and end tags for events

if [system][syslog][message] =~ "Line protocol on Interface Tunnel[0-9]+, changed state to down" {  
mutate { add\_tag =\> ["tunnelDOWN"] }  
}  
if [system][syslog][message] =~ "Line protocol on Interface Tunnel[0-9]+, changed state to up" {  
mutate { add\_tag =\> ["tunnelUP"] }  
}

# Measure the execution time between events

elapsed {  
start\_tag =\> "tunnelDOWN"  
end\_tag =\> "tunnelUP"  
unique\_id\_field =\> "messageID"  
new\_event\_on\_match =\> true  
}

}

output {  
stdout { codec =\> rubydebug { metadata =\> true} }  
}

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 1, 2019, 9:45am UTC](https://discuss.elastic.co/t/elapsed-filter-ends-in-elapsed-end-without-start/183874/4 "2019-07-01T09:45:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
