# Logstash Aggregate with multiple end tags

**URL:** https://discuss.elastic.co/t/logstash-aggregate-with-multiple-end-tags/232972
**Category:** Logstash
**Created:** [May 17, 2020, 7:13am UTC](https://discuss.elastic.co/t/logstash-aggregate-with-multiple-end-tags/232972 "2020-05-17T07:13:44Z")
**Posts on this page:** 1
**Showing post:** 2

<div class="post-metadata">

### Author: ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)
#### Post date: [May 17, 2020, 7:41am UTC](https://discuss.elastic.co/t/logstash-aggregate-with-multiple-end-tags/232972/2 "2020-05-17T07:41:37Z")

</div>

if you are sure that the event tag only have either Saved or Saved, Modified , then you can access the modified timestamp with %{event\_tag[1]}. since they are on the same column, i imagine the eveng\_tag will be in array.

then you could go with :

```
if “Modified” in [event_tag] { 
  filter { 
    #elapsed filter with %{event_tag[1]} as end value 
  } 
} 

else { 
  filter {
     #elapsed filter with %{event_tag[0]} as end value
  } 
} 

```

the best way will be using ruby filter to extract the time stamp from either Saved or Modified. [Here’s](https://discuss.elastic.co/t/how-do-i-use-an-array-field-as-a-variable-in-logstash/55545) an example

---

_[View the full topic](https://discuss.elastic.co/t/logstash-aggregate-with-multiple-end-tags/232972)._
