# Event generated after timeout is not being pushed to elasticsearch

**URL:** <https://discuss.elastic.co/t/event-generated-after-timeout-is-not-being-pushed-to-elasticsearch/132096>\
**Category:** Logstash\
**Created:** [May 16, 2018, 10:40am UTC](https://discuss.elastic.co/t/event-generated-after-timeout-is-not-being-pushed-to-elasticsearch/132096 "2018-05-16T10:40:55Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![vchandrashekar](https://avatars.discourse-cdn.com/v4/letter/v/f07891/32.png) [@vchandrashekar](https://discuss.elastic.co/u/vchandrashekar)\
**Post date:** [May 16, 2018, 10:40am UTC](https://discuss.elastic.co/t/event-generated-after-timeout-is-not-being-pushed-to-elasticsearch/132096/1 "2018-05-16T10:40:55Z")

</div>

Hi All,

## I have following logstash configuration:

input {  
file {  
type =\> "fail"  
path =\> "/filepath/ag.txt"  
}  
}

filter {  
grok {  
match =\> ["message", "%{LOGLEVEL:loglevel} - %{NOTSPACE:user\_id} - %{GREEDYDATA:msg\_text}"]  
}

aggregate {  
task\_id =\> "%{user\_id}"  
code =\> "map['clicks'] ||= 0; map['clicks'] += 1;  
map['several\_clicks'] = false;  
"  
push\_map\_as\_event\_on\_timeout =\> true  
timeout\_task\_id\_field =\> "user\_id"  
timeout =\> 30  
timeout\_tags =\> ['\_aggregatetimeout']  
timeout\_code =\> "event.set('several\_clicks', event.get('clicks') \> 1);"  
}  
}  
output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "%{type}\_agindex"  
action =\> "update"  
document\_id =\> "%{user\_id}"  
document\_type =\> "doc"  
doc\_as\_upsert =\> "true"  
}  
stdout { codec =\> rubydebug }  
}

* * *

following is the input file:

INFO - 12345 - Clicked One  
INFO - 12345 - Clicked Two  
INFO - 12345 - Clicked Three  
INFO - 12346 - Clicked One  
INFO - 12346 - Clicked Two  
INFO - 12346 - Clicked Three

All the events gets generated appropriately. For the above input, 2 events gets generated and 2 documents are created in elastic search.

## After a timeout of 30 seconds, we get two more events as below:

## { "several\_clicks" =\> true, "tags" =\> [[0] "\_aggregatetimeout" ], "clicks" =\> 3, "@version" =\> "1", "@timestamp" =\> 2018-05-16T10:25:33.024Z, "user\_id" =\> "12345" } { "several\_clicks" =\> true, "tags" =\> [[0] "\_aggregatetimeout" ], "clicks" =\> 3, "@version" =\> "1", "@timestamp" =\> 2018-05-16T10:25:33.025Z, "user\_id" =\> "12346" }

These events are not pushed to elastic search.

This is same example as provided here : [https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html#plugins-filters-aggregate-example3](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html#plugins-filters-aggregate-example3)

Please let me know what is missing in my configuration.

Thanks

# V.Chandrashekar

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 13, 2018, 10:40am UTC](https://discuss.elastic.co/t/event-generated-after-timeout-is-not-being-pushed-to-elasticsearch/132096/2 "2018-06-13T10:40:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
