# Kibana visualization for time difference

**URL:** <https://discuss.elastic.co/t/kibana-visualization-for-time-difference/115993>\
**Category:** Kibana\
**Created:** [January 18, 2018, 8:21am UTC](https://discuss.elastic.co/t/kibana-visualization-for-time-difference/115993 "2018-01-18T08:21:58Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Bikash\_Behuria](https://avatars.discourse-cdn.com/v4/letter/b/f14d63/32.png) [@Bikash\_Behuria](https://discuss.elastic.co/u/Bikash_Behuria)\
**Post date:** [January 18, 2018, 8:21am UTC](https://discuss.elastic.co/t/kibana-visualization-for-time-difference/115993/1 "2018-01-18T08:21:58Z")

</div>

Hi ,

I have Request Response Integration logs with correlation ID in both request and response logs.

5c023e43-b695-407b-ac17-1f85d10ec9e4 RP401 OPT OrderId 11087766 (Request)  
5c023e43-b695-407b-ac17-1f85d10ec9e4 RS401 OPT OrderId 11087766 (Response)

And elasticsearch timestamp field as well. And the first field is the CorrelationId and format JSON is like below

{  
"\_index": "applicationlogs",  
"\_type": "applicationlogs",  
"\_id": "AWEIM3fktvuk7rH85tyK",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
"@timestamp": "2018-01-18T07:37:26.210Z",  
"system": "OPT",  
"messagetype": "RS401",  
"businessIdType": "OrderId",  
"CorelationId": "5c023e43-b695-407b-ac17-1f85d10ec9e4",  
"@version": "1",  
"businessId": "11087766",  
"message": "5c023e43-b695-407b-ac17-1f85d10ec9e4 RS401 OPT OrderId 11087766",  
"type": "applicationlogs",  
"tags": [  
"\_jsonparsefailure"  
]  
},  
"fields": {  
"@timestamp": [  
1516261046210  
]  
},  
"sort": [  
1516261046210  
]  
}

Now my requirement is to find out the time difference between Request and Response and based on that , I want to create some Visualization.

Can someone please help ?

Thanks-Bikash

---

<div class="post-metadata">

**Author:** ![lukas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lukas/32/6812_2.png) [@lukas](https://discuss.elastic.co/u/lukas)\
**Post date:** [January 18, 2018, 8:21pm UTC](https://discuss.elastic.co/t/kibana-visualization-for-time-difference/115993/2 "2018-01-18T20:21:54Z")

</div>

I can't think of a way to do this without further enriching your data prior to indexing in Elasticsearch. Are you able to add a step prior to indexing that adds the time difference to the document corresponding to the response?

---

<div class="post-metadata">

**Author:** ![Bikash\_Behuria](https://avatars.discourse-cdn.com/v4/letter/b/f14d63/32.png) [@Bikash\_Behuria](https://discuss.elastic.co/u/Bikash_Behuria)\
**Post date:** [January 18, 2018, 8:59pm UTC](https://discuss.elastic.co/t/kibana-visualization-for-time-difference/115993/3 "2018-01-18T20:59:46Z")

</div>

Hi ,

Since this is a request reply async pattern , my one process sending request , so I am logging the request time and another process receiving response , then I am logging the response time. The common field is the correlation Id , which I am sending in both logs. So it will be two log statement received in two different time.

My pipeline is like below

Application --\> Kafka topic --\> Logstash --\> Elasticsearch --\> Kibana

I am sending this logs via Logstash using Grok filter to parse . I was searching a solution using elasticsearch query , and then wanted to show the visulaization in Kibana.

Thanks-Bikash

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 15, 2018, 9:00pm UTC](https://discuss.elastic.co/t/kibana-visualization-for-time-difference/115993/4 "2018-02-15T21:00:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
