# How to calculate time difference between 2 log lines for a unique ID

**URL:** <https://discuss.elastic.co/t/how-to-calculate-time-difference-between-2-log-lines-for-a-unique-id/155870>\
**Category:** Kibana\
**Created:** [November 8, 2018, 11:15am UTC](https://discuss.elastic.co/t/how-to-calculate-time-difference-between-2-log-lines-for-a-unique-id/155870 "2018-11-08T11:15:22Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roshan\_r](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roshan_r/32/9760_2.png) [@Roshan\_r](https://discuss.elastic.co/u/Roshan_r)\
**Post date:** [November 8, 2018, 11:15am UTC](https://discuss.elastic.co/t/how-to-calculate-time-difference-between-2-log-lines-for-a-unique-id/155870/1 "2018-11-08T11:15:22Z")

</div>

I need to calculate the difference in time between 2 log lines for http code 200. The difference should be done for a unique id. Please find the log line below.

```
2018/01/16 00:13:44.890 [HCServiceImpl] [**qtp5720769-243**]: AUDIT- INFO: Request received : /mdp/content?sourceType=cid&amp;pset=mdp%3Ano-presentation&amp;filter%3AcontentId=cid%3A%2F%2Fprogramid%253A%252F%252F2090543776%23programid%253A%252F%252F1264605229

2018/01/16 00:13:44.897 [HCServiceImpl] [**qtp5720769-243**]: AUDIT- INFO: Returning response code : 200

```

Here qtp5720769-243 is the Unique ID. Then check for 200. Then calculate the time between [00:13:44.897] & [00:13:44.890]. I am not sure how to do this. Is this achievable using scripted field?

---

<div class="post-metadata">

**Author:** ![Joe\_Fleming](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_fleming/32/3561_2.png) [@Joe\_Fleming](https://discuss.elastic.co/u/Joe_Fleming)\
**Post date:** [November 8, 2018, 6:28pm UTC](https://discuss.elastic.co/t/how-to-calculate-time-difference-between-2-log-lines-for-a-unique-id/155870/2 "2018-11-08T18:28:06Z")

</div>

Elasticsearch doesn't support that kind of operation at query time, you'd have to do it another way. Or, maybe you could use [pipeline aggs](https://www.elastic.co/guide/en/elasticsearch/reference/current/search-aggregations-pipeline.html), but I don't really understand how those work enough to even tell you if that's something they can be used for. Kibana has some support for them, you could play around and see.

You could get that data at ingest time though by enriching it and adding a new field with that value. Basically, you check to see when the newest previous document with the same criteria, calculate the difference on the document you're about to index, and then index it with that calculation. Something like [injest node](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html) (you can read more about that [here](https://www.elastic.co/blog/new-way-to-ingest-part-1)) or log logstash should help.

If you need to do this at query time, you could figure out the difference using two queries and a little math, but Kibana doesn't support that.

---

<div class="post-metadata">

**Author:** ![Roshan\_r](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roshan_r/32/9760_2.png) [@Roshan\_r](https://discuss.elastic.co/u/Roshan_r)\
**Post date:** [November 9, 2018, 11:29am UTC](https://discuss.elastic.co/t/how-to-calculate-time-difference-between-2-log-lines-for-a-unique-id/155870/3 "2018-11-09T11:29:30Z")

</div>

Thanks for the reply. I will check for the information you provided.

---

<div class="post-metadata">

**Author:** ![Petr.Simik](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/petr.simik/32/38082_2.png) [@Petr.Simik](https://discuss.elastic.co/u/Petr.Simik)\
**Post date:** [November 27, 2018, 5:39am UTC](https://discuss.elastic.co/t/how-to-calculate-time-difference-between-2-log-lines-for-a-unique-id/155870/4 "2018-11-27T05:39:07Z")

</div>

I am trying to resolve the same problem using logstash using elasticsearch filter  
see example  
[https://www.elastic.co/guide/en/logstash/current/lookup-enrichment.html](https://www.elastic.co/guide/en/logstash/current/lookup-enrichment.html)  
in principle during parsing of line it checks if type == end , query index to search for start  
retrieve data and do calculation of duration

the problem of this approach:  
if there are 2 lines close to each other, the query is executed too fast (before the first line is inserted into elastic index) so it does not retrieve the data.  
It works only if the process is slowed down or if there is enough lines between these two lines to give logstash time to PUT the first line into index.

---

<div class="post-metadata">

**Author:** ![Roshan\_r](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roshan_r/32/9760_2.png) [@Roshan\_r](https://discuss.elastic.co/u/Roshan_r)\
**Post date:** [November 28, 2018, 2:46am UTC](https://discuss.elastic.co/t/how-to-calculate-time-difference-between-2-log-lines-for-a-unique-id/155870/5 "2018-11-28T02:46:26Z")

</div>

Thanks Petr

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 26, 2018, 2:46am UTC](https://discuss.elastic.co/t/how-to-calculate-time-difference-between-2-log-lines-for-a-unique-id/155870/6 "2018-12-26T02:46:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
