# Get time elapsed between two different documents

**URL:** <https://discuss.elastic.co/t/get-time-elapsed-between-two-different-documents/55935>\
**Category:** Kibana\
**Created:** [July 19, 2016, 10:42pm UTC](https://discuss.elastic.co/t/get-time-elapsed-between-two-different-documents/55935 "2016-07-19T22:42:04Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andre\_Leite](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_leite/32/10967_2.png) [@Andre\_Leite](https://discuss.elastic.co/u/Andre_Leite)\
**Post date:** [July 19, 2016, 10:42pm UTC](https://discuss.elastic.co/t/get-time-elapsed-between-two-different-documents/55935/1 "2016-07-19T22:42:04Z")

</div>

How can I make a query in Discovery that only show me different documents for different events sharing a common field like Session-Id that the time elapsed between two consecutive events is less than a certain amount of time?  
For instance:

Session-Id: 123, Type: Start, time: 01:00  
Session-Id: 123, Type: Update, time: 01:10  
Session-Id: 123, Type: Stop, time: 01:15

Session-Id: 321, Type: Start, time:02:00  
Session-Id: 321, Type: Update, time: 03:00

So I don't want to see the document with the Session-Id field 321 for it has two events 1 hour apart from each other, but the one with Session-Id 123 should show up on my query.

Is there a way to achieve this without using the elapsed logstash filter? I also would have to account for like 5 different type values, so even using elapsed logstash filter that would be a bit tricky I guess.

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [July 21, 2016, 7:47am UTC](https://discuss.elastic.co/t/get-time-elapsed-between-two-different-documents/55935/2 "2016-07-21T07:47:45Z")

</div>

I would look into use a scripted field to calculate the difference between the Start and End time, or if you can calculate it on the document when it's inserted.

---

<div class="post-metadata">

**Author:** ![LeeDr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leedr/32/9289_2.png) [@LeeDr](https://discuss.elastic.co/u/LeeDr)\
**Post date:** [July 21, 2016, 7:14pm UTC](https://discuss.elastic.co/t/get-time-elapsed-between-two-different-documents/55935/3 "2016-07-21T19:14:54Z")

</div>

You can also look at this;

> [@Display concurrency in data on Kibana](https://discuss.elastic.co/t/display-concurrency-in-data-on-kibana/26006/12):
>
> I also tried this but it doesn't remove the field parameter as promised. With the following json input: { "interval":"minute", "script": "start = doc['recordStart'].value; duration = doc['recordDuration'].value; l = []; for (long i = 0; i \< duration; i += 60000) { l.add(start + i); }; return l;", "field":null, "lang": "groovy" } I get the following request "aggs": { "2": { "date\_histogram": { "field": null, "interval": "minute", "pre\_zone": "+02:00", "pre\_zone\_adjust\_large…

---

<div class="post-metadata">

**Author:** ![Andre\_Leite](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_leite/32/10967_2.png) [@Andre\_Leite](https://discuss.elastic.co/u/Andre_Leite)\
**Post date:** [July 23, 2016, 7:09pm UTC](https://discuss.elastic.co/t/get-time-elapsed-between-two-different-documents/55935/4 "2016-07-23T19:09:02Z")

</div>

Can I use scripted fields for fields that are not numbers? For timestamps, for instance.. and for different events too?

---

<div class="post-metadata">

**Author:** ![Andre\_Leite](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_leite/32/10967_2.png) [@Andre\_Leite](https://discuss.elastic.co/u/Andre_Leite)\
**Post date:** [July 23, 2016, 7:09pm UTC](https://discuss.elastic.co/t/get-time-elapsed-between-two-different-documents/55935/5 "2016-07-23T19:09:16Z")

</div>

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 1:44pm UTC](https://discuss.elastic.co/t/get-time-elapsed-between-two-different-documents/55935/6 "2017-07-06T13:44:33Z")

</div>


