# Elapsed time filter is not calculating the time correctly

**URL:** <https://discuss.elastic.co/t/elapsed-time-filter-is-not-calculating-the-time-correctly/286418>\
**Category:** Logstash\
**Created:** [October 11, 2021, 9:28pm UTC](https://discuss.elastic.co/t/elapsed-time-filter-is-not-calculating-the-time-correctly/286418 "2021-10-11T21:28:06Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Indigo\_Star](https://avatars.discourse-cdn.com/v4/letter/i/ba8739/32.png) [@Indigo\_Star](https://discuss.elastic.co/u/Indigo_Star)\
**Post date:** [October 11, 2021, 9:28pm UTC](https://discuss.elastic.co/t/elapsed-time-filter-is-not-calculating-the-time-correctly/286418/1 "2021-10-11T21:28:06Z")

</div>

Hi,

I am using an elapsed time plugin, as per the documentation the elapsed-time is calculated in seconds. I am calculating the values on a unique field basis "seq". Here is what i am getting, In the snapshot the second event is the start event and first one is the end event which contains the elapsed-time value. but looking at the time stamps the calculated values doesn't seem correct.  
both timestamps are same except the ms part.

ms is 221 in the end event and 193 in the start event which should be 0.028 sec and 28 ms but the elapsed time field is showing "1,027,052" which is very wrong. Can you please help understanding it?

Thanks

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f5eaa4f283956a90cbcc37df4cda15760f85924e.png)

---

<div class="post-metadata">

**Author:** ![Indigo\_Star](https://avatars.discourse-cdn.com/v4/letter/i/ba8739/32.png) [@Indigo\_Star](https://discuss.elastic.co/u/Indigo_Star)\
**Post date:** [October 12, 2021, 2:45am UTC](https://discuss.elastic.co/t/elapsed-time-filter-is-not-calculating-the-time-correctly/286418/2 "2021-10-12T02:45:10Z")

</div>

Hi,

I realized that this problem is happening because of loading the offline logs.

I need to work with offline logs. and since elapsed filter uses @timestamp to calculate the "elapsed\_time" field so it is not working as expected.

@Badger Is there anyway to tell elapsed filter to use custom field like i have log\_timestamp to calculate the "elapsed\_field" and assign the same to the "elapsed\_time\_start" instead of using @timestamp.

Following is the snap shot indicates the time difference between actual log time and the load time and calculated values of the elapsed\_time.

I don't know if we can replace the value of @timestamp using mutate filter by the log\_timestamp. If we can do this then i think it will be resolved.

Thanks

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/7/d/7d51a3bae5eb011c1706ad75657218a9dcabf067.png)

---

<div class="post-metadata">

**Author:** ![Indigo\_Star](https://avatars.discourse-cdn.com/v4/letter/i/ba8739/32.png) [@Indigo\_Star](https://discuss.elastic.co/u/Indigo_Star)\
**Post date:** [October 12, 2021, 3:12am UTC](https://discuss.elastic.co/t/elapsed-time-filter-is-not-calculating-the-time-correctly/286418/3 "2021-10-12T03:12:00Z")

</div>

OK i tried this

```auto
date {
        match => ["log-time", "yyyy-MM-dd HH:mm:ss,SSS"]
      
		target => "@timestamp"
      }

```

replaced the timestamp value now my elapsed filter is working as expected.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2021, 3:12am UTC](https://discuss.elastic.co/t/elapsed-time-filter-is-not-calculating-the-time-correctly/286418/4 "2021-11-09T03:12:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
