# How to do Calculation in Elasticsearch Query

**URL:** <https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496>\
**Category:** Elasticsearch\
**Created:** [January 19, 2023, 10:25am UTC](https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496 "2023-01-19T10:25:09Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [January 19, 2023, 10:25am UTC](https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496/1 "2023-01-19T10:25:09Z")

</div>

Hi there,

to continue discussion below, I decided to create a new topic. please read the topic below first so you can understand it.

> [@How to Show the Value of tags When Using Server Log Connector](https://discuss.elastic.co/t/how-to-show-the-value-of-tags-when-using-server-log-connector/323372/1):
>
> Hello everyone, i want to ask something about alerting here. i already create a rule to notify me if there is a certificate that will be expire in few days through server log which is kibana.log like this [image] [image] Due to different types of certificates that exist, in which there is manual-renew and auto-renew, I want to display those tags in the message. so that the script that I made can be given conditions(if else) based on the value of field tags. What variables can I use to displa…

OK, so the next question is how if i use elasticsearch query to calculate expire date of a certificate using field below and I subtract it with today's date. is it possible?  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/3/2380681541a64462d022773bc6ef89e35bfb8572.png)

if that is possible, maybe i can call the value of the tags field too so that my script can work with that

Thanks

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 19, 2023, 2:43pm UTC](https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496/2 "2023-01-19T14:43:47Z")

</div>

You know Uptime/ Heartbeat does all that for you...cert check and alert.

But yes you can create a runtime field to calculate the difference assuming you are on a fairly recent version.

I had a post on that let me look

Perhaps this will help

> [@Calculate elapsed time in Kibana?](https://discuss.elastic.co/t/calculate-elapsed-time-in-kibana/316575/2):
>
> Hi @TXBigDawg1836 Welcome to the community Yup add a runtime field to the Data View here is the code long datenow = new Date().getTime(); long datewas = doc['@timestamp'].value.getMillis(); emit (datenow - datewas); Create / Set the Field Chose your format.... In Discover Now Table...

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [January 20, 2023, 1:11am UTC](https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496/3 "2023-01-20T01:11:21Z")

</div>

> [@stephenb](#):
>
> You know Uptime/ Heartbeat does all that for you...cert check and alert.

sure, but i need to call the value of the tags field from heartbeat index to separate cert that have auto-renew tags, and manual-renew tags and it's not possible with TLS Cert type

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 20, 2023, 1:13am UTC](https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496/4 "2023-01-20T01:13:49Z")

</div>

Ok...Did you look at the example I gave you? It shows how to calculate elapsed time. You could add a runtime field to your mapping and it would always be available for you.

You could tag the cert checks as well heartbeat if you know the types when you can figure... Then the data would be there.

---

<div class="post-metadata">

**Author:** ![yuswanul](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yuswanul/32/101662_2.png) [@yuswanul](https://discuss.elastic.co/u/yuswanul)\
**Post date:** [January 20, 2023, 1:27am UTC](https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496/5 "2023-01-20T01:27:30Z")

</div>

do you have example for 7.17 version? i didn't found Data Views menu in stack management here

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 20, 2023, 1:39am UTC](https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496/6 "2023-01-20T01:39:44Z")

</div>

It's under index pattern which is the 7.17 version of data views. Data views came in 8.x.

You can test it out in the index pattern, but if it's something that you're going to use quite a bit or query against you will actually need to add it to the mapping.

Get it working in the index pattern first which then you'll be able to see it in discover first and then we can translate it over to the mapping

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 17, 2023, 1:40am UTC](https://discuss.elastic.co/t/how-to-do-calculation-in-elasticsearch-query/323496/7 "2023-02-17T01:40:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
