# Elapsed time between consecutive logs

**URL:** <https://discuss.elastic.co/t/elapsed-time-between-consecutive-logs/97216>\
**Category:** Logstash\
**Created:** [August 16, 2017, 9:04am UTC](https://discuss.elastic.co/t/elapsed-time-between-consecutive-logs/97216 "2017-08-16T09:04:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Robert\_Kovacs](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@Robert\_Kovacs](https://discuss.elastic.co/u/Robert_Kovacs)\
**Post date:** [August 16, 2017, 9:04am UTC](https://discuss.elastic.co/t/elapsed-time-between-consecutive-logs/97216/1 "2017-08-16T09:04:52Z")

</div>

I know a quite similar question was raised in [Time between timestamp](https://discuss.elastic.co/t/time-between-timestamp/32137) but a clear answer wasn't given there.

I would like to calculate the difference between every consecutive logs timestamp and insert the result as a new field in the latter log.  
I guess the elapsed filter is my best bet, but I am rather new to logstash and I couldn't find out how I should do it.  
Any help would be appreciated.

---

<div class="post-metadata">

**Author:** ![Shaoranlaos](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Shaoranlaos](https://discuss.elastic.co/u/Shaoranlaos)\
**Post date:** [August 16, 2017, 10:09am UTC](https://discuss.elastic.co/t/elapsed-time-between-consecutive-logs/97216/2 "2017-08-16T10:09:59Z")

</div>

i don't think you could do that with the elapsed filter because for him an event can only be a start event for the timer **OR** an end event.

I think your only possibility will be the ruby filter.

---

<div class="post-metadata">

**Author:** ![Robert\_Kovacs](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@Robert\_Kovacs](https://discuss.elastic.co/u/Robert_Kovacs)\
**Post date:** [August 16, 2017, 11:38am UTC](https://discuss.elastic.co/t/elapsed-time-between-consecutive-logs/97216/3 "2017-08-16T11:38:56Z")

</div>

Any idea on how can I get the timestamp of the previous log with ruby? With that the problem should be solved.

---

<div class="post-metadata">

**Author:** ![Shaoranlaos](https://avatars.discourse-cdn.com/v4/letter/s/c57346/32.png) [@Shaoranlaos](https://discuss.elastic.co/u/Shaoranlaos)\
**Post date:** [August 16, 2017, 12:00pm UTC](https://discuss.elastic.co/t/elapsed-time-between-consecutive-logs/97216/4 "2017-08-16T12:00:58Z")

</div>

You can saved it in a variable of the ruby plugin (needs worker set to 1 like the elapsed plugin to give always the correct value)  
it should be something like this:

```
ruby {
    ruby {
        init => "$last_time = 0.0;"
        code => "event.set('elapsed_time', event.get('@timestamp').to_f-$last_time); $last_time = event.get('@timestamp').to_f;"
    }
}

```

untested because i didn't have a test system handy where i can test this

EDIT: ok i have tested it now there where some errors in there that i have now fixed and it has now a higher precision (not only down to 1s)

---

<div class="post-metadata">

**Author:** ![Robert\_Kovacs](https://avatars.discourse-cdn.com/v4/letter/r/4491bb/32.png) [@Robert\_Kovacs](https://discuss.elastic.co/u/Robert_Kovacs)\
**Post date:** [August 17, 2017, 9:23am UTC](https://discuss.elastic.co/t/elapsed-time-between-consecutive-logs/97216/5 "2017-08-17T09:23:09Z")

</div>

Thank you for the help. It seems to work fine.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2017, 9:23am UTC](https://discuss.elastic.co/t/elapsed-time-between-consecutive-logs/97216/6 "2017-09-14T09:23:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
