# Elapsed Filter

**URL:** <https://discuss.elastic.co/t/elapsed-filter/26198>\
**Category:** Elasticsearch\
**Created:** [July 24, 2015, 3:08am UTC](https://discuss.elastic.co/t/elapsed-filter/26198 "2015-07-24T03:08:17Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![bdunbar](https://avatars.discourse-cdn.com/v4/letter/b/a3d4f5/32.png) [@bdunbar](https://discuss.elastic.co/u/bdunbar)\
**Post date:** [July 24, 2015, 3:08am UTC](https://discuss.elastic.co/t/elapsed-filter/26198/1 "2015-07-24T03:08:17Z")

</div>

I've got 9 apache servers feeding data into Elasticsearch via Logstash, front-end is Kibana 4.

One of the items they want me to visualize is Average Visitor Stay Length. It was suggested in another thread that I could use the [elapsed filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elapsed.html) to calculate the value and store in elasticsearch.

Assuming I can make it work, I can apply it to all data being fed into the system. **_Is there a way to apply a logstash filter to the data I've already stored in elasticsearch?_** I've got 18 months of log file data _in_ the system now I'd like to mangle it in place if possible.

(I can see a crude way to apply it. Given that I have the log file data on disk and the indexes are date-time based: use a script to delete the index for the day, use logstash to put it back _in_ with the new filter in addition to the rest but .. man that seems tedious. Say .. is there an export function ...)

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 24, 2015, 3:42am UTC](https://discuss.elastic.co/t/elapsed-filter/26198/2 "2015-07-24T03:42:26Z")

</div>

You will need to reindex the data to get this.

---

<div class="post-metadata">

**Author:** ![bdunbar](https://avatars.discourse-cdn.com/v4/letter/b/a3d4f5/32.png) [@bdunbar](https://discuss.elastic.co/u/bdunbar)\
**Post date:** [July 24, 2015, 2:34pm UTC](https://discuss.elastic.co/t/elapsed-filter/26198/3 "2015-07-24T14:34:47Z")

</div>

Looks like I'm about to learn something.

Reading [this](https://www.elastic.co/guide/en/elasticsearch/guide/current/reindex.html), it appears to be a fairly straightforward process. And this brings forward another question;

I've been getting by, so far, using bash to import data, and some basic operations on the cluster and nodes using the [cat API](https://www.elastic.co/guide/en/elasticsearch/reference/current/cat.html). Would it be optimal instead to spend a few hours learning to use one of the [clients](https://www.elastic.co/guide/en/elasticsearch/client/community/current/clients.html) instead?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 24, 2015, 11:27pm UTC](https://discuss.elastic.co/t/elapsed-filter/26198/4 "2015-07-24T23:27:29Z")

</div>

Your call 😛  
I just use Logstash!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 5, 2017, 11:59pm UTC](https://discuss.elastic.co/t/elapsed-filter/26198/5 "2017-07-05T23:59:05Z")

</div>


