# How to calculate timediff (in milliseconds) of two fields in the same event

**URL:** <https://discuss.elastic.co/t/how-to-calculate-timediff-in-milliseconds-of-two-fields-in-the-same-event/151711>\
**Category:** Logstash\
**Created:** [October 9, 2018, 9:06pm UTC](https://discuss.elastic.co/t/how-to-calculate-timediff-in-milliseconds-of-two-fields-in-the-same-event/151711 "2018-10-09T21:06:12Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Dawn\_Okem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dawn_okem/32/58264_2.png) [@Dawn\_Okem](https://discuss.elastic.co/u/Dawn_Okem)\
**Post date:** [October 9, 2018, 9:06pm UTC](https://discuss.elastic.co/t/how-to-calculate-timediff-in-milliseconds-of-two-fields-in-the-same-event/151711/1 "2018-10-09T21:06:13Z")

</div>

My question is similar to the one asked [here](https://discuss.elastic.co/t/how-to-calculate-timediff-of-two-fields-in-the-same-event/106417) but i want to be able to get the time difference in milliseconds.

I saw a ruby solution [here](https://discuss.elastic.co/t/logstash-ruby-filter-to-subtract-difference-between-two-timestamps-in-single-event/32580/4), but how do i modify the code to give me the difference in milliseconds instead of in seconds.

My date time fields are in the format "09/10/2018 21:59:26.816" i.e. dd/mm/yyyy HH:MM:ss.SSS

---

<div class="post-metadata">

**Author:** ![Dawn\_Okem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dawn_okem/32/58264_2.png) [@Dawn\_Okem](https://discuss.elastic.co/u/Dawn_Okem)\
**Post date:** [October 10, 2018, 8:32pm UTC](https://discuss.elastic.co/t/how-to-calculate-timediff-in-milliseconds-of-two-fields-in-the-same-event/151711/2 "2018-10-10T20:32:59Z")

</div>

so i was able to write the code in ruby.

```
require 'time'

received_at = '09/10/2018 22:07:19.966' 
sent_at = '09/10/2018 22:07:20.509' 

sentrub = (Time.parse(sent_at).to_f)*1000
recirub = (Time.parse(received_at).to_f)*1000

delta = sentrub - recirub

puts sentrub
puts recirub
puts delta

```

have to find a way of writing/using it in logstash. 😀😀😀

---

<div class="post-metadata">

**Author:** ![Ganesh\_Venkataraman](https://avatars.discourse-cdn.com/v4/letter/g/a4c791/32.png) [@Ganesh\_Venkataraman](https://discuss.elastic.co/u/Ganesh_Venkataraman)\
**Post date:** [October 11, 2018, 3:55am UTC](https://discuss.elastic.co/t/how-to-calculate-timediff-in-milliseconds-of-two-fields-in-the-same-event/151711/3 "2018-10-11T03:55:38Z")

</div>

Please check if this is of any help to you.

```
date{
  match => ["tds_audittimestamp", "UNIX_MS"]
  timezone => "UTC"
  target => "tds_audittimestamp"
}
date{
  match => ["effective_timestamp", "UNIX_MS"]
  timezone => "UTC"
  target => "effective_timestamp"
}

#Generate end-2-end latency for messages with below criteria only.
if [msg_type] == "ON_MESSAGE" and [msg_status] == "END" and [effective_timestamp] != "null" and [tds_audittimestamp] != "null" {
    ruby {
        init => "require 'time'"
        code => "
            startdatetime = event.get('effective_timestamp');
            enddatetime = event.get('tds_audittimestamp');
                                                            timetaken = (enddatetime - startdatetime) rescue nil;
            event.set('latency_seconds_e2e',timetaken);
            "
    }
}
```

---

<div class="post-metadata">

**Author:** ![Dawn\_Okem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dawn_okem/32/58264_2.png) [@Dawn\_Okem](https://discuss.elastic.co/u/Dawn_Okem)\
**Post date:** [October 11, 2018, 11:00pm UTC](https://discuss.elastic.co/t/how-to-calculate-timediff-in-milliseconds-of-two-fields-in-the-same-event/151711/4 "2018-10-11T23:00:51Z")

</div>

Thank you very much @Ganesh_Venkataraman. I had written a similar ruby code [here](https://discuss.elastic.co/t/logstash-errors-while-executing-ruby-code-ruby-exception-occurred-allocator-undefined-for-floa/151939). but it fails with a ruby code exception " ```  
Ruby exception occurred: allocator undefined for Float

```auto

    	date {
    		match => ["received_at", "dd/mm/yyyy HH:mm:ss.SSS"]
    		timezone => "UTC"
    		target => "receivedlogtime"
    	  }
    	  
    	date {
    		match => ["sent_at", "dd/mm/yyyy HH:mm:ss.SSS"]
    		timezone => "UTC"
    		target => "sentlogtime"
    	  }
    	  
    	  
    	if [received_at] and [sent_at] {
    		ruby {
    			init => "require 'time'"
    			code => "
    				received_by_finacle = (Time.parse(event.get('received_at')).to_f)*1000;
    				sent_out_by_finacle = (Time.parse(event.get('sent_at')).to_f)*1000;
    				timetaken = (sent_out_by_finacle - received_by_finacle) rescue nil;
    				event.set('time_delta',timetaken);
    				event.set('epoch_received_at_in_milliseconds',received_by_finacle);
    				event.set('epoch_sent_at_in_milliseconds',sent_out_by_finacle);
    				"
    				add_tag => ["calculated_time_difference"]
    		}
    	}    

Thank you very much
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 8, 2018, 11:00pm UTC](https://discuss.elastic.co/t/how-to-calculate-timediff-in-milliseconds-of-two-fields-in-the-same-event/151711/5 "2018-11-08T23:00:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
