I think you could just do something like:
ruby {
    init => "require 'time'"
    code => "event['time_difference'] = event['received_at'] - event['@timestamp'];"
}
            I think you could just do something like:
ruby {
    init => "require 'time'"
    code => "event['time_difference'] = event['received_at'] - event['@timestamp'];"
}
            © 2020. All Rights Reserved - Elasticsearch
Apache, Apache Lucene, Apache Hadoop, Hadoop, HDFS and the yellow elephant logo are trademarks of the Apache Software Foundation in the United States and/or other countries.