# How to implement task life cycle scenario

**URL:** <https://discuss.elastic.co/t/how-to-implement-task-life-cycle-scenario/248128>\
**Category:** Logstash\
**Created:** [September 10, 2020, 7:59am UTC](https://discuss.elastic.co/t/how-to-implement-task-life-cycle-scenario/248128 "2020-09-10T07:59:34Z")\
**Posts on this page:** 1\
**Showing post:** 6

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 14, 2020, 3:11pm UTC](https://discuss.elastic.co/t/how-to-implement-task-life-cycle-scenario/248128/6 "2020-09-14T15:11:17Z")

</div>

If you want to find the time for which a ticket was open you could use

```
    json { source => "message" remove_field => ["message"] }
    date { match => ["log_time", "dd/MM/YYYY HH:mm:ss.SSS"] }
    if [event] == "CREATED" {
        aggregate {
            task_id => "%{job_id}"
            code => 'map["start_time"] = event.get("@timestamp")'
            map_action => "create"
        }
    }

    if [event] == "CLOSED" {
        aggregate {
            task_id => "%{job_id}"
            code => 'event.set("duration", event.get("@timestamp") - map["start_time"])'
            map_action => "update"
            end_of_task => true
            timeout => 10
        }
    }

```

If your concern is that tickets can be open for a very long time then you could use an approach like [this](https://discuss.elastic.co/t/aggregate-problem/142572/7).

The number of tickets created/closed in a time period and the average time a ticket was open are questions I would answer using elasticsearch, not logstash.

---

_[View the full topic](https://discuss.elastic.co/t/how-to-implement-task-life-cycle-scenario/248128)._
