# How to parse a TimeSpan value which displays the difference between to timestamps

**URL:** <https://discuss.elastic.co/t/how-to-parse-a-timespan-value-which-displays-the-difference-between-to-timestamps/246502>\
**Category:** Logstash\
**Created:** [August 26, 2020, 6:28pm UTC](https://discuss.elastic.co/t/how-to-parse-a-timespan-value-which-displays-the-difference-between-to-timestamps/246502 "2020-08-26T18:28:14Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![pheathers](https://avatars.discourse-cdn.com/v4/letter/p/67e7ee/32.png) [@pheathers](https://discuss.elastic.co/u/pheathers)\
**Post date:** [August 26, 2020, 6:28pm UTC](https://discuss.elastic.co/t/how-to-parse-a-timespan-value-which-displays-the-difference-between-to-timestamps/246502/1 "2020-08-26T18:28:15Z")

</div>

I'm trying to parse through a timespan value (hh:mm:ss:SSSSSS). Here is the message ...

```
`2020-08-05 13:28:53.128 +03:00 [DBG] {"Timestamp":"2020-08-05T13:28:53.1286882+03:00","Profile":"db","ProcessID":26688,"SessionId":"0","Message":"SELECT column1, column2 FROM hsi.table","TimeSpan":"00:00:00.0019088","LogLevel":"Debug",,"Direction":"Out","AppPoolName":"Server"}`

```

I would like to store the **TimeSpan** value as a sortable column. I looked at this [link](https://discuss.elastic.co/t/parsing-execution-metrics-which-are-represented-as-timespan/2274), but didn't follow how it worked and it didn't include the milliseconds.

My **logstash.config** uses the following filter settings.

```auto
filter {
    mutate{
        gsub => ["message", "^.{1,37}(.*)$","\1"]
    }
    json{
        source=> "message"      
    }  
    grok {
		match => { 
			 "TimeSpan" => { "%{INT:hours}:%{INT:minutes}:%{INT:seconds}.%{INT:miliseconds}" }
		}            
    }	
	date {
		match => ["Timestamp", "ISO8601"]
	}	
}

```

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 26, 2020, 7:39pm UTC](https://discuss.elastic.co/t/how-to-parse-a-timespan-value-which-displays-the-difference-between-to-timestamps/246502/2 "2020-08-26T19:39:28Z")

</div>

That example predates the event API. You can no longer directly reference the event as a hash. These days it would be

```
    grok { match => { "TimeSpan" => "%{INT:hours}:%{INT:minutes}:%{INT:seconds}.%{INT:subsecond}" } }
    date { match => ["Timestamp", "ISO8601"] }
    ruby {
        code => '
            subsecond = event.get("subsecond")
            subsecond = subsecond.to_f / (10 ** subsecond.length)
            event.set("elapsed", 3600 * event.get("hours").to_f + 60 * event.get("minutes").to_f + event.get("seconds").to_f + subsecond)
        '
        remove_field => ["hours", "minutes", "seconds", "subsecond"]
    }

```

The 10 \*\* stuff for subsecond ensure that it can handle time spans like "01:02:03.2". Note that your JSON is not valid since it has ,, just after the LogLevel.

---

<div class="post-metadata">

**Author:** ![pheathers](https://avatars.discourse-cdn.com/v4/letter/p/67e7ee/32.png) [@pheathers](https://discuss.elastic.co/u/pheathers)\
**Post date:** [August 26, 2020, 7:53pm UTC](https://discuss.elastic.co/t/how-to-parse-a-timespan-value-which-displays-the-difference-between-to-timestamps/246502/3 "2020-08-26T19:53:27Z")

</div>

Thanks you @Badger. I'll give that a try.

The double ,, was a typo as I was cleaning up the JSON to post it. Good eyes. 😉

---

<div class="post-metadata">

**Author:** ![pheathers](https://avatars.discourse-cdn.com/v4/letter/p/67e7ee/32.png) [@pheathers](https://discuss.elastic.co/u/pheathers)\
**Post date:** [August 26, 2020, 9:51pm UTC](https://discuss.elastic.co/t/how-to-parse-a-timespan-value-which-displays-the-difference-between-to-timestamps/246502/4 "2020-08-26T21:51:37Z")

</div>

Follow up... when I start Logstash I get the following error

`Ruby exception occurred: undefined method 'length' for nil:NilClass`

The error seems to be coming from this line

`subsecond = subsecond.to_f / (10 ** subsecond.length)`

Any thoughts on how I can resolve it?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 26, 2020, 10:42pm UTC](https://discuss.elastic.co/t/how-to-parse-a-timespan-value-which-displays-the-difference-between-to-timestamps/246502/5 "2020-08-26T22:42:55Z")

</div>

You did update the grok to refer to subsecond instead of milisecond, right?

---

<div class="post-metadata">

**Author:** ![pheathers](https://avatars.discourse-cdn.com/v4/letter/p/67e7ee/32.png) [@pheathers](https://discuss.elastic.co/u/pheathers)\
**Post date:** [August 27, 2020, 1:34pm UTC](https://discuss.elastic.co/t/how-to-parse-a-timespan-value-which-displays-the-difference-between-to-timestamps/246502/6 "2020-08-27T13:34:52Z")

</div>

Yes, I updated it to the following ...

```auto
	grok { 
		match => { 
			"TimeSpan" => "%{INT:hours}:%{INT:minutes}:%{INT:seconds}.%{INT:subsecond}" 			
		} 
	}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 27, 2020, 3:20pm UTC](https://discuss.elastic.co/t/how-to-parse-a-timespan-value-which-displays-the-difference-between-to-timestamps/246502/7 "2020-08-27T15:20:11Z")

</div>

> [@pheathers](#):
>
> Ruby exception occurred: undefined method 'length' for nil:NilClass

That is telling you that the [subsecond] field does not exist. You could change the ruby code to

```
subsecond = event.get("subsecond")
if subsecond
    subsecond = subsecond.to_f / (10 ** subsecond.length)
    event.set("elapsed", 3600 * event.get("hours").to_f + 60 * event.get("minutes").to_f + event.get("seconds").to_f + subsecond)
end

```

---

<div class="post-metadata">

**Author:** ![pheathers](https://avatars.discourse-cdn.com/v4/letter/p/67e7ee/32.png) [@pheathers](https://discuss.elastic.co/u/pheathers)\
**Post date:** [August 27, 2020, 5:29pm UTC](https://discuss.elastic.co/t/how-to-parse-a-timespan-value-which-displays-the-difference-between-to-timestamps/246502/8 "2020-08-27T17:29:45Z")

</div>

Thanks @Badger. I'll give that a try. Appreciate the help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 24, 2020, 5:29pm UTC](https://discuss.elastic.co/t/how-to-parse-a-timespan-value-which-displays-the-difference-between-to-timestamps/246502/9 "2020-09-24T17:29:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
