# Find current event logs

**URL:** <https://discuss.elastic.co/t/find-current-event-logs/236349>\
**Category:** Kibana\
**Tags:** painless\
**Created:** [June 9, 2020, 1:36pm UTC](https://discuss.elastic.co/t/find-current-event-logs/236349 "2020-06-09T13:36:56Z")\
**Posts on this page:** 12\
**Page:** 1

<div class="post-metadata">

**Author:** ![Joshua\_Tetteh\_Ocanse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_tetteh_ocanse/32/63885_2.png) [@Joshua\_Tetteh\_Ocanse](https://discuss.elastic.co/u/Joshua_Tetteh_Ocanse)\
**Post date:** [June 9, 2020, 1:36pm UTC](https://discuss.elastic.co/t/find-current-event-logs/236349/1 "2020-06-09T13:36:56Z")

</div>

Hello

I have set of log documents categorized with event-ids which is string in form of timestamp.  
I want to find the document with the earliest timestamp so I can always visualize the current set of logs.

This is what I have done with scripted field but not working, please I need help.

````auto
```painless
 def event_latest = 0L; 
    for (def i = 0; i < doc['event_id'].length; i++) {
    def current_date = doc['event_id'][i].getValue().toInstant().toEpochMilli();
         if (current_date > event_latest)
            event_latest = current_date;
     }
    return event_latest;

````

```auto

```

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [June 9, 2020, 1:40pm UTC](https://discuss.elastic.co/t/find-current-event-logs/236349/2 "2020-06-09T13:40:16Z")

</div>

If `event_id` is of type string and not date, you have to parse it first - see [https://www.elastic.co/guide/en/elasticsearch/painless/master/painless-datetime.html#\_datetime\_parsing\_examples](https://www.elastic.co/guide/en/elasticsearch/painless/master/painless-datetime.html#_datetime_parsing_examples) for examples how to do it.

---

<div class="post-metadata">

**Author:** ![Joshua\_Tetteh\_Ocanse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_tetteh_ocanse/32/63885_2.png) [@Joshua\_Tetteh\_Ocanse](https://discuss.elastic.co/u/Joshua_Tetteh_Ocanse)\
**Post date:** [June 10, 2020, 9:21pm UTC](https://discuss.elastic.co/t/find-current-event-logs/236349/3 "2020-06-10T21:21:50Z")

</div>

@flash1293 . Thanks for your suggestion. I parsed into date but did not work.

Maybe someone can help me modify the code, I want to find the latest document based on the event\_id (timestamp).

Sorry for late in reply.

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [June 11, 2020, 8:45am UTC](https://discuss.elastic.co/t/find-current-event-logs/236349/4 "2020-06-11T08:45:00Z")

</div>

Can you share the code where you attempt the date parsing? An example document would also be helpful to find a solution.

---

<div class="post-metadata">

**Author:** ![Joshua\_Tetteh\_Ocanse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_tetteh_ocanse/32/63885_2.png) [@Joshua\_Tetteh\_Ocanse](https://discuss.elastic.co/u/Joshua_Tetteh_Ocanse)\
**Post date:** [June 12, 2020, 1:23pm UTC](https://discuss.elastic.co/t/find-current-event-logs/236349/5 "2020-06-12T13:23:31Z")

</div>

@flash1293

Thank you. This is my code below:

```
 def event_latest = 0L; 
    for (def i = 0; i < doc['indexer_job_id'].length; i++) {
    def datetime = doc['indexer_job_id'][i].getValue().toInstant().toEpochMilli();
    ZonedDateTime current_date = ZonedDateTime.parse(datetime);
         if (current_date > event_latest)
            event_latest = current_date;
     }
    return event_latest;

```

I still get shards failures !!

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [June 12, 2020, 1:27pm UTC](https://discuss.elastic.co/t/find-current-event-logs/236349/6 "2020-06-12T13:27:26Z")

</div>

Can you show an example of an `indexer_event_id`?

---

<div class="post-metadata">

**Author:** ![Joshua\_Tetteh\_Ocanse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_tetteh_ocanse/32/63885_2.png) [@Joshua\_Tetteh\_Ocanse](https://discuss.elastic.co/u/Joshua_Tetteh_Ocanse)\
**Post date:** [June 12, 2020, 1:29pm UTC](https://discuss.elastic.co/t/find-current-event-logs/236349/7 "2020-06-12T13:29:32Z")

</div>

indexer\_job\_id is an event-id in a form of string eg. "2020-05-28T00:03:00.001106Z"

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [June 12, 2020, 1:36pm UTC](https://discuss.elastic.co/t/find-current-event-logs/236349/8 "2020-06-12T13:36:08Z")

</div>

You have to call parse with the value from the doc, you can only call `toInstant` on an already parsed date:

```auto
def d = ZonedDateTime.parse(doc['indexer_job_id'][i].getValue());
def timestamp = d.toInstant().toEpochMilli();

```

But re-reading your question I'm not even sure whether the thing you want to do is possible using scripted fields. To you want to find the latest event id within the current document (`indexer_job_id` being an array field with multiple entries), or are there multiple documents you want to find the latest?

For the first use case this is the right approach, but it's not for the latter one. A scripted field is executed once for each document, you can't look up values within other documents inside of it.

To visualize the value of a field from the latest document in the current time range, you can use a metric visualization and the "Top Hit" aggregation. If `indexer_job_id` is always a date, you should specify it as date in the index mapping, then Elasticsearch will know how to handle it.

---

<div class="post-metadata">

**Author:** ![Joshua\_Tetteh\_Ocanse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_tetteh_ocanse/32/63885_2.png) [@Joshua\_Tetteh\_Ocanse](https://discuss.elastic.co/u/Joshua_Tetteh_Ocanse)\
**Post date:** [June 12, 2020, 1:51pm UTC](https://discuss.elastic.co/t/find-current-event-logs/236349/9 "2020-06-12T13:51:47Z")

</div>

Thanks @flash1293.  
Yes, it is the later, I want to find the latest event of multiple documents so I can dynamically visual the values of the latest event; ie I want visualisation that will always find the latest values of the current or latest event not manually with a specific event\_id.

If not possible with scripted field, Is any approach to dynamically visualized values based on the latest event. ?

---

<div class="post-metadata">

**Author:** ![flash1293](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/flash1293/32/41227_2.png) [@flash1293](https://discuss.elastic.co/u/flash1293)\
**Post date:** [June 12, 2020, 1:52pm UTC](https://discuss.elastic.co/t/find-current-event-logs/236349/10 "2020-06-12T13:52:23Z")

</div>

See the last paragraph in my previous post.

---

<div class="post-metadata">

**Author:** ![Joshua\_Tetteh\_Ocanse](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joshua_tetteh_ocanse/32/63885_2.png) [@Joshua\_Tetteh\_Ocanse](https://discuss.elastic.co/u/Joshua_Tetteh_Ocanse)\
**Post date:** [June 12, 2020, 1:56pm UTC](https://discuss.elastic.co/t/find-current-event-logs/236349/11 "2020-06-12T13:56:00Z")

</div>

Thanks @flash1293 . I will try that and give you feedback.

Best regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2020, 1:56pm UTC](https://discuss.elastic.co/t/find-current-event-logs/236349/12 "2020-07-10T13:56:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
