# Make a duration field based of field's value

**URL:** <https://discuss.elastic.co/t/make-a-duration-field-based-of-fields-value/381058>\
**Category:** Elasticsearch\
**Created:** [August 14, 2025, 8:20pm UTC](https://discuss.elastic.co/t/make-a-duration-field-based-of-fields-value/381058 "2025-08-14T20:20:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [August 14, 2025, 8:20pm UTC](https://discuss.elastic.co/t/make-a-duration-field-based-of-fields-value/381058/1 "2025-08-14T20:20:09Z")

</div>

Hello,

I am ingesting a field that changes value and I would like to capture a duration of the value, is this possible with Elastic?

> For example:  
> 13:00 - 1 document - **field1** : “Offline” , **newfield\_duration** : 0min  
> 13:04 - 1 document - **field1** : “Offline”, **newfield\_duration** : 4min
> 
> 13:05 - 1 document - **field1** : “Online”, **newfield\_duration** : 0min

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [August 15, 2025, 2:02am UTC](https://discuss.elastic.co/t/make-a-duration-field-based-of-fields-value/381058/2 "2025-08-15T02:02:52Z")

</div>

Hello @erikg

As per the example shared how do you derive newfield\_duration? Online =\> Offline?  
For 1st example both field1 are Offline? Do we have any common field like say ID?

```auto
13:00 - 1 document - ID1 - field1: “Online” , newfield_duration: 0min
13:04 - 1 document - ID1 - field1: “Offline”, newfield_duration: 4min

13:05 - 1 document - ID2 - field1: “Online”, newfield_duration: 0min
13:14 - 1 document - ID2 - field1: “Offline”, newfield_duration: 9min

```

If you could share more details or example then it might be helpful.

Thanks!!

---

<div class="post-metadata">

**Author:** ![erikg](https://avatars.discourse-cdn.com/v4/letter/e/91b2a8/32.png) [@erikg](https://discuss.elastic.co/u/erikg)\
**Post date:** [August 22, 2025, 5:06pm UTC](https://discuss.elastic.co/t/make-a-duration-field-based-of-fields-value/381058/3 "2025-08-22T17:06:00Z")

</div>

Hey @Tortoise , yes you are correct about a common id would be used.

I think what I am looking for is something like this:  
`id1: “alarm_1” , field1: ”Offline”, newfield_duration: 1day`  
`id1: “alarm_2” , field1: ”Online”, newfield_duration: 30min`

This essentially tells me that an `alarm_1` has been offline for 1day and `alarm_2` has been online for 30 minutes.

I was thinking deeper into this,  
It seems like I essentially need to like a transform? an aggregation on the max timestamp and and aggregation on the min timestamp?

---

<div class="post-metadata">

**Author:** ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)\
**Post date:** [August 23, 2025, 5:48am UTC](https://discuss.elastic.co/t/make-a-duration-field-based-of-fields-value/381058/4 "2025-08-23T05:48:16Z")

</div>

Hello @erikg

Yes, transform will help to capture the data id wise & field1 (latest).  
If possible could you share few log lines as i was wondering will this data be written every 5 minutes and the newfield\_duration will be currenttime - timestamp of record?

Thanks!!
