# Filebeat iis module time taken field

**URL:** <https://discuss.elastic.co/t/filebeat-iis-module-time-taken-field/275504>\
**Category:** Beats\
**Tags:** beats-module\
**Created:** [June 9, 2021, 10:02pm UTC](https://discuss.elastic.co/t/filebeat-iis-module-time-taken-field/275504 "2021-06-09T22:02:28Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [June 10, 2021, 3:35am UTC](https://discuss.elastic.co/t/filebeat-iis-module-time-taken-field/275504/2 "2021-06-10T03:35:49Z")

</div>

Yes and `event.duration`

So if you look at the definition of event.duration [here](https://www.elastic.co/guide/en/beats/filebeat/current/exported-fields-ecs.html)

`event.duration`

Duration of the event in **nanoseconds**. If event.start and event.end are known this value should be the difference between the end and start time.

```auto
type: long
format: duration

```

So it looks like it is turned from **ms** (probably what the `ctx.temp.duration) it is _ **multiplied** _ by 1,000,000 in the pipeline to become nanoseconds.

Take a look at a discussion in [this](https://discuss.elastic.co/t/reason-for-scale-1000000-for-iis-event-duration/273762) thread

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-iis-module-time-taken-field/275504)._
