# Help to calculate start time from disconnection time and session time

**URL:** <https://discuss.elastic.co/t/help-to-calculate-start-time-from-disconnection-time-and-session-time/36607>\
**Category:** Logstash\
**Created:** [December 8, 2015, 7:15am UTC](https://discuss.elastic.co/t/help-to-calculate-start-time-from-disconnection-time-and-session-time/36607 "2015-12-08T07:15:26Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![cdgraff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cdgraff/32/6484_2.png) [@cdgraff](https://discuss.elastic.co/u/cdgraff)\
**Post date:** [December 8, 2015, 7:15am UTC](https://discuss.elastic.co/t/help-to-calculate-start-time-from-disconnection-time-and-session-time/36607/1 "2015-12-08T07:15:26Z")

</div>

Hi all,

I'm trying to get the StartTime of a session from my icecast streaming logs, into the logs I has the Disconnection date and the session duration time.

In simple math need to be something like this:  
new timestamp = event[@timestamp] - event['duration']\*1000

But I can't made this works, my code that is not working is:

```
            date {
                  	match => ["timestamp" , "dd/MMM/YYYY:HH:mm:ss Z"]
            }
            ruby {
                  	init => "require 'time'"
                    code => "event['@timestamp'] = event['timestamp'] - (event['duration']*1000);"
            }

```

I got this error:

> Ruby exception occurred: undefined method `-' for "08/Sep/2015:09:35:23 -0600":String {:level=\>:error}

Thanks in advance for any advice!  
Alejandro

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 8, 2015, 7:24am UTC](https://discuss.elastic.co/t/help-to-calculate-start-time-from-disconnection-time-and-session-time/36607/2 "2015-12-08T07:24:55Z")

</div>

The `timestamp` and `@timestamp` fields are strings. If you want to perform time math on them you have to parse them into a Time with e.g. Time.parse(). Be careful about timezone issues and converting back to the expected format for `@timestamp`. It might be easier to convert it to an epoch and use a separate date filter for getting that into `@timestamp`.

---

<div class="post-metadata">

**Author:** ![cdgraff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cdgraff/32/6484_2.png) [@cdgraff](https://discuss.elastic.co/u/cdgraff)\
**Post date:** [December 8, 2015, 9:24pm UTC](https://discuss.elastic.co/t/help-to-calculate-start-time-from-disconnection-time-and-session-time/36607/3 "2015-12-08T21:24:44Z")

</div>

thanks @magnusbaeck, i'm really newbie with Ruby and I try to do this time convertion without success

This be the current code:  
`code => "event['timestamp_new'] = Time.parse(event['@timestamp']).to_i - event['duration']"`

Some advice to understand what i'm doing wrong?

Thanks in advance!  
Alejandro

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 8, 2015, 9:37pm UTC](https://discuss.elastic.co/t/help-to-calculate-start-time-from-disconnection-time-and-session-time/36607/4 "2015-12-08T21:37:13Z")

</div>

In what way is it not working? Have you tried the code in a standalone Ruby interpreter like irb?

---

<div class="post-metadata">

**Author:** ![cdgraff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cdgraff/32/6484_2.png) [@cdgraff](https://discuss.elastic.co/u/cdgraff)\
**Post date:** [December 10, 2015, 4:17am UTC](https://discuss.elastic.co/t/help-to-calculate-start-time-from-disconnection-time-and-session-time/36607/5 "2015-12-10T04:17:00Z")

</div>

@magnusbaeck the error i got now is:

Ruby exception occurred: undefined method `gsub!' for "2015-09-08T15:56:58.000Z":LogStash::Timestamp {:level=>:error}`

I googled this error, but look really generic.

If I try this Date from IRB look that works well  
irb(main):016:0\> Time.parse('2015-09-08T15:56:58.000Z').to\_i  
=\> 1441727818

Look like I has this error:

> <https://github.com/logstash-plugins/logstash-output-datadog_metrics/issues/3>

Some advice to fix? i can't understand what i need to change to fix...  
Thanks

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 10, 2015, 6:35am UTC](https://discuss.elastic.co/t/help-to-calculate-start-time-from-disconnection-time-and-session-time/36607/6 "2015-12-10T06:35:47Z")

</div>

Ah, right. The `@timestamp` field contains a [LogStash::Timestamp](https://github.com/elastic/logstash/blob/master/logstash-core-event/lib/logstash/timestamp.rb) object rather than a string. Since that class overloads the subtraction operator I suspect you can just do

```
event['timestamp_new'] = event['@timestamp'] - event['duration']

```

provided that the `duration` field is an integer and not a string.

---

<div class="post-metadata">

**Author:** ![cdgraff](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cdgraff/32/6484_2.png) [@cdgraff](https://discuss.elastic.co/u/cdgraff)\
**Post date:** [December 10, 2015, 1:19pm UTC](https://discuss.elastic.co/t/help-to-calculate-start-time-from-disconnection-time-and-session-time/36607/7 "2015-12-10T13:19:52Z")

</div>

thanks!

If I try like the example:

> event['timestamp\_new'] = event['@timestamp'] - event['duration']

I got:  
`Ruby exception occurred: no implicit conversion to rational from nil {:level=>:error}`

If I do:

> event['timestamp\_new'] = event['@timestamp'].to\_i - event['duration'].to\_i

Logstash start correctly and run, but don't insert any information into ES and don't show any error into logs and CPU use is really high...

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 10, 2015, 1:23pm UTC](https://discuss.elastic.co/t/help-to-calculate-start-time-from-disconnection-time-and-session-time/36607/8 "2015-12-10T13:23:13Z")

</div>

> I got:  
> Ruby exception occurred: no implicit conversion to rational from nil {:level=\>:error}

Do _all_ events have `duration` fields?

> Logstash start correctly and run, but don't insert any information into ES and don't show any error into logs and CPU use is really high...

Increasing the logging verbosity with `--verbose` or `--debug` might help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:19am UTC](https://discuss.elastic.co/t/help-to-calculate-start-time-from-disconnection-time-and-session-time/36607/9 "2017-07-06T05:19:06Z")

</div>


