# Groking duration

**URL:** <https://discuss.elastic.co/t/groking-duration/126146>\
**Category:** Logstash\
**Created:** [March 29, 2018, 6:53pm UTC](https://discuss.elastic.co/t/groking-duration/126146 "2018-03-29T18:53:01Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Milan\_Kaliraj](https://avatars.discourse-cdn.com/v4/letter/m/c89c15/32.png) [@Milan\_Kaliraj](https://discuss.elastic.co/u/Milan_Kaliraj)\
**Post date:** [March 29, 2018, 6:53pm UTC](https://discuss.elastic.co/t/groking-duration/126146/1 "2018-03-29T18:53:01Z")

</div>

HI ,  
How can we grok **duration** field for following piece of message:

"Duration: 0h:00m:16s, Bytes xmt: 76895, Bytes rcv: 81897, Reason: User Requested"

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 29, 2018, 7:10pm UTC](https://discuss.elastic.co/t/groking-duration/126146/2 "2018-03-29T19:10:07Z")

</div>

What do you want to end up with?

---

<div class="post-metadata">

**Author:** ![Milan\_Kaliraj](https://avatars.discourse-cdn.com/v4/letter/m/c89c15/32.png) [@Milan\_Kaliraj](https://discuss.elastic.co/u/Milan_Kaliraj)\
**Post date:** [March 29, 2018, 7:24pm UTC](https://discuss.elastic.co/t/groking-duration/126146/3 "2018-03-29T19:24:41Z")

</div>

i want to grok **duration** to a timestamp so that i can create queries based on duration ( i.e. highest online time of user ) or based on highest sum of TX & RX bytes of user.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 29, 2018, 8:38pm UTC](https://discuss.elastic.co/t/groking-duration/126146/4 "2018-03-29T20:38:41Z")

</div>

If you test something like this

```auto
  grok { match => { "message" => "Duration: %{NUMBER:hours}h:%{NUMBER:minutes}m:%{NUMBER:seconds}s, Bytes xmt: %{NUMBER:xmt}, Bytes rcv: %{NUMBER:rcv}, Reason: %{GREEDYDATA:reason}" } }
  mutate { add_field => { "time" => "%{hours}:%{minutes}:%{seconds}" } }
  date { match => ["time", "H:mm:ss"] target => "duration1" }
  ruby { code => 'event.set("duration2", event.get("hours").to_i*3600 + event.get("minutes").to_i*60 + event.get("seconds").to_i)' }
  mutate { remove_field => ["hours", "minutes", "seconds"] }

```

You will end up the datetime picking up default values for the year, etc. Which is probably not what you want. Converting it to a number of seconds might work better.

```auto
     "message" => "Duration: 1h:10m:16s, Bytes xmt: 76895, Bytes rcv: 81897, Reason: User Requested",
     "duration1" => 2018-01-01T06:10:16.000Z,
     "duration2" => 4216,

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 26, 2018, 8:39pm UTC](https://discuss.elastic.co/t/groking-duration/126146/5 "2018-04-26T20:39:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
