# Logstash filter issue

**URL:** <https://discuss.elastic.co/t/logstash-filter-issue/335314>\
**Category:** Logstash\
**Created:** [June 6, 2023, 10:19am UTC](https://discuss.elastic.co/t/logstash-filter-issue/335314 "2023-06-06T10:19:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![namdev](https://avatars.discourse-cdn.com/v4/letter/n/a88e4f/32.png) [@namdev](https://discuss.elastic.co/u/namdev)\
**Post date:** [June 6, 2023, 10:19am UTC](https://discuss.elastic.co/t/logstash-filter-issue/335314/1 "2023-06-06T10:19:53Z")

</div>

Hi team,

I am using logstash filter to get the duration between two dates.

StartDate =2023-05-23T 10:25:53.123Z  
EndDate =2023-05-23T 18:25:43.123Z  
using the code below:--

```plaintext
            match => ["Start Date", "ISO8601"]
            target => "start_date"
        }
date {
            match => ["End Date", "ISO8601"]
            target => "end_date"
        }
        

ruby {
      init => "require 'time' "
      Code=> "event.set('duration', event.get('end_date').to_f - event.get('start_date').to_f )
 "
  }

```

In one machine it's showing proper output in second as (ex-34526.234) but in another machine for same code it's showing (1243678889.788) 10 digit output .

Is it the issue of time in Date filter?  
Or any other issue?

Any help would be thankful.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 6, 2023, 6:57pm UTC](https://discuss.elastic.co/t/logstash-filter-issue/335314/2 "2023-06-06T18:57:52Z")

</div>

> [@namdev](#):
>
> 1243678889.788

If the StartDate field is missing then you will just get the result of parsing EndDate, which in recent years would be a 10-digit number.

---

<div class="post-metadata">

**Author:** ![namdev](https://avatars.discourse-cdn.com/v4/letter/n/a88e4f/32.png) [@namdev](https://discuss.elastic.co/u/namdev)\
**Post date:** [June 6, 2023, 7:35pm UTC](https://discuss.elastic.co/t/logstash-filter-issue/335314/3 "2023-06-06T19:35:14Z")

</div>

Thanks burger , but I have checked both dates are present in the ingested data.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 6, 2023, 7:41pm UTC](https://discuss.elastic.co/t/logstash-filter-issue/335314/4 "2023-06-06T19:41:08Z")

</div>

If you showed us a sample event using `output { stdout { codec => rubydebug } }` we might be able to work it out.

---

<div class="post-metadata">

**Author:** ![namdev](https://avatars.discourse-cdn.com/v4/letter/n/a88e4f/32.png) [@namdev](https://discuss.elastic.co/u/namdev)\
**Post date:** [June 12, 2023, 5:34pm UTC](https://discuss.elastic.co/t/logstash-filter-issue/335314/5 "2023-06-12T17:34:55Z")

</div>

Hi burger,  
In the output part I am using like this

```auto
 Output {

   Elasticsearch {
          I'd => "main_es" 
          Host=> ["localhost:9200"]
           
          index => "%{[@metadata][indexname]}"
          I'd => "%{I'd}"
         sniffing=true
         action= update
         doc_as_upcert=> true

}
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2023, 5:35pm UTC](https://discuss.elastic.co/t/logstash-filter-issue/335314/6 "2023-07-10T17:35:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
