# Elapsed plugin not detecting start tag

**URL:** https://discuss.elastic.co/t/elapsed-plugin-not-detecting-start-tag/156369
**Category:** Logstash
**Created:** [November 13, 2018, 2:14am UTC](https://discuss.elastic.co/t/elapsed-plugin-not-detecting-start-tag/156369 "2018-11-13T02:14:09Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![chickennuggets](https://avatars.discourse-cdn.com/v4/letter/c/5daacb/32.png) [@chickennuggets](https://discuss.elastic.co/u/chickennuggets)
#### Post date: [November 13, 2018, 2:14am UTC](https://discuss.elastic.co/t/elapsed-plugin-not-detecting-start-tag/156369/1 "2018-11-13T02:14:09Z")

</div>

I've noticed that the elapsed filter has not been detecting a large amount of my start/end tagged events. I tend to see the "elapsed\_end\_without\_start" tag added to my end tagged events, as well as "elapsed\_expired\_error" events being generated.

I was wondering if this is a common problem when processing nearly 5,000 events every 30 minutes or if there's a possible workaround to it.

---

<div class="post-metadata">

### Author: ![chickennuggets](https://avatars.discourse-cdn.com/v4/letter/c/5daacb/32.png) [@chickennuggets](https://discuss.elastic.co/u/chickennuggets)
#### Post date: [November 14, 2018, 10:10am UTC](https://discuss.elastic.co/t/elapsed-plugin-not-detecting-start-tag/156369/2 "2018-11-14T10:10:55Z")

</div>

Update: Still haven't found any solutions to the problem. If anybody has any ideas, that'd be great.

---

<div class="post-metadata">

### Author: ![marvin\_sonar](https://avatars.discourse-cdn.com/v4/letter/m/7bcc69/32.png) [@marvin\_sonar](https://discuss.elastic.co/u/marvin_sonar)
#### Post date: [November 17, 2018, 4:58pm UTC](https://discuss.elastic.co/t/elapsed-plugin-not-detecting-start-tag/156369/3 "2018-11-17T16:58:36Z")

</div>

I'm having the same problem. Haven't figured out any solutions yet.

---

<div class="post-metadata">

### Author: ![chickennuggets](https://avatars.discourse-cdn.com/v4/letter/c/5daacb/32.png) [@chickennuggets](https://discuss.elastic.co/u/chickennuggets)
#### Post date: [November 19, 2018, 4:32am UTC](https://discuss.elastic.co/t/elapsed-plugin-not-detecting-start-tag/156369/4 "2018-11-19T04:32:54Z")

</div>

A little bit of backstory.

My logs are all related to transactions (basically requests and responses). I'm trying to find the transactions which have a request, but don't have the corresponding response, a.k.a a dropped transaction.

Since all of them have a unique id (transaction\_id), I figured I'd use the elapsed filter and set the start\_tag to the request and the end\_tag to the response. From there I'd be able to view the transaction id of the dropped transactions as elapsed would generate new events containing the transaction id and the tag, "elapsed\_expired\_error". However, I'm facing the problem above.

So, if anybody has a different method to solving this or even an idea to point me in the right direction, I'd love to hear it and it'd be greatly appreciated.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 17, 2018, 4:33am UTC](https://discuss.elastic.co/t/elapsed-plugin-not-detecting-start-tag/156369/5 "2018-12-17T04:33:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
