# Make event wait

**URL:** <https://discuss.elastic.co/t/make-event-wait/100983>\
**Category:** Logstash\
**Created:** [September 19, 2017, 8:08am UTC](https://discuss.elastic.co/t/make-event-wait/100983 "2017-09-19T08:08:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [September 19, 2017, 8:08am UTC](https://discuss.elastic.co/t/make-event-wait/100983/1 "2017-09-19T08:08:28Z")

</div>

Hi,

Can I make that if I get a log that parameter X = 'a' that Logstash will not push it straight to ES but wait for 3 minutes?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 19, 2017, 8:09am UTC](https://discuss.elastic.co/t/make-event-wait/100983/2 "2017-09-19T08:09:30Z")

</div>

The only way to do that would be to pause the entire pipeline, maybe with a ruby hack (note: I call it a hack because it is, Logstash is not designed for this)

---

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [September 19, 2017, 8:14am UTC](https://discuss.elastic.co/t/make-event-wait/100983/3 "2017-09-19T08:14:13Z")

</div>

Understood, the reason I am trying this hack is b/c "push\_map\_as\_event\_on\_timeout =\> true" doesn't work for me...  
at the end of timeout I dont have a new log containing all the map

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 19, 2017, 8:15am UTC](https://discuss.elastic.co/t/make-event-wait/100983/4 "2017-09-19T08:15:12Z")

</div>

Perhaps if you provided more detail on the problem others can help?

---

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [September 19, 2017, 8:24am UTC](https://discuss.elastic.co/t/make-event-wait/100983/5 "2017-09-19T08:24:27Z")

</div>

Yes, well I am able to aggregate that my last log has all the terms, but I can't know who will be my last log, therefore I did "push\_map\_as\_event\_on\_timeout =\> true" (I kept all config that is not repetitive since maybe some part that I didn't think of destroys the push map.

This is suppose to print out a new log after 120 seconds isn't it? (for me it is not working)

Here is my LS config:

```
input {
 ...
}

filter {
  json{
        source => "message"
  }

  aggregate {
		task_id => "%{transactionId}"
		code => "
			
			if (map['authCBGot'])
				event.set('authCBGot', (map['authCBGot']))
			else 
				if (event.get('authCBGot').eql? '0')
					# do nothing
				else
					map['authCBGot'] = event.get('authCBGot')
				end
			end
			... (many more as the "authCBGot")
			"
		push_map_as_event_on_timeout => true
		timeout_task_id_field => "transactionId"
		timeout => 120
		timeout_code => "event.set('cdrType', 'aggregated')"
    
   }
   
  if [ASR]{
	  mutate {
		convert => { "ASR" => "float" }
	  }
  }
  
  date {
    match => ["eventTimestamp", "UNIX_MS"]
    target => "eventTimestamp"
  }
  ...(many more Date filters)
  
 (some ruby)
  if [medGotAck_MT] and [MedGotMsgFromApi] {
    ruby {
      init => "require 'time'"
      code => "
					medGotAck_MT = Time.iso8601(event.get('medGotAck_MT').to_s).to_i;
					MedGotMsgFromApi = Time.iso8601(event.get('MedGotMsgFromApi').to_s).to_i;
					event.set('delay' , medGotAck_MT - MedGotMsgFromApi);
					if (event.get('cdrType').eql? 'dlr')
						if (event.get('MedGotMsgFromApi').eql? '0')
							event.set('delay' , 120);
						else
							event.set('delay' , medGotAck_MT - MedGotMsgFromApi);
						end
					else
						event.set('delay' , medGotAck_MT - MedGotMsgFromApi);
					end
					event.set('epoch_received_at_in_seconds' , medGotAck_MT);
					event.set('epoch_timestamp_in_seconds' , MedGotMsgFromApi);
				"
			
    }
  }
  
  
	 
}

output {
    elasticsearch {
      hosts => ["192.168.1.116:9200"]
      manage_template => false
      index => "%{[@metadata][beat]}-%{+YYYY.MM.dd}"
      document_type => "%{[@metadata][type]}"
  }
  

}
```

---

<div class="post-metadata">

**Author:** ![tomer](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@tomer](https://discuss.elastic.co/u/tomer)\
**Post date:** [September 19, 2017, 8:30am UTC](https://discuss.elastic.co/t/make-event-wait/100983/6 "2017-09-19T08:30:11Z")

</div>

@warkolm should I ask this also as a new topic?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 17, 2017, 8:30am UTC](https://discuss.elastic.co/t/make-event-wait/100983/7 "2017-10-17T08:30:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
