# How to calculate and present times between logs

**URL:** <https://discuss.elastic.co/t/how-to-calculate-and-present-times-between-logs/313324>\
**Category:** Logstash\
**Created:** [August 31, 2022, 7:40am UTC](https://discuss.elastic.co/t/how-to-calculate-and-present-times-between-logs/313324 "2022-08-31T07:40:08Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 31, 2022, 9:32pm UTC](https://discuss.elastic.co/t/how-to-calculate-and-present-times-between-logs/313324/2 "2022-08-31T21:32:37Z")

</div>

You could use an aggregate filter to do that

```
    if [message] =~ /"@Moving":"/ {
        grok { match => { "message" => '{"@time":"(?<[@metadata][timestamp]>[^"]+)" "@Moving":"(?<[@metadata][msg]>[^"]+)"' } }
        mutate { add_field => { "[@metadata][json]" => '{ "@timestamp": "%{[@metadata][timestamp]}" }' } }
        json { source => "[@metadata][json]" }

        mutate { add_field => { "[@metadata][taskId]" => "anyConstant" } }
        if [@metadata][msg] =~ /^</ {
            aggregate {
                task_id => "%{[@metadata][taskId]}"
                code => 'map["startTime"] = event.get("@timestamp").to_f'
                map_action => "create"
            }
        } else {
            aggregate {
                task_id => "%{[@metadata][taskId]}"
                code => 'event.set("delta", event.get("@timestamp").to_f - map["startTime"])'
                map_action => "update"
                end_of_task => true
            }
        }
    }

```

which will produce

```
     "delta" => 181.1056525707245,

```

for the second pair of lines. Note that using aggregate requires pipeline.workers to be 1 and pipeline.ordered to be true.

---

_[View the full topic](https://discuss.elastic.co/t/how-to-calculate-and-present-times-between-logs/313324)._
