# Mapping and Scripting

**URL:** <https://discuss.elastic.co/t/mapping-and-scripting/192315>\
**Category:** Kibana\
**Created:** [July 25, 2019, 8:06pm UTC](https://discuss.elastic.co/t/mapping-and-scripting/192315 "2019-07-25T20:06:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Karthik2411](https://avatars.discourse-cdn.com/v4/letter/k/ed8c4c/32.png) [@Karthik2411](https://discuss.elastic.co/u/Karthik2411)\
**Post date:** [July 25, 2019, 8:06pm UTC](https://discuss.elastic.co/t/mapping-and-scripting/192315/1 "2019-07-25T20:06:11Z")

</div>

I have two fields named "kafkaTimestamp" and "sparkprocesstime" I want to script the difference between those two fields. The mapping of the two fields are as follows:

kafka\_timestamp

```auto
"kafka_timestamp" : {
            "type" : "text",
            "fields" : {
              "keyword" : {
                "type" : "keyword",
                "ignore_above" : 256
              }
            }
          }

```

Spark process time

```auto
"spark_process_time" : {
            "type" : "date"
          }

```

Now I want know how I can convert the kafka time stamp into a date and then I want to look for the difference between those two by writing a scripted field.

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [July 26, 2019, 11:09pm UTC](https://discuss.elastic.co/t/mapping-and-scripting/192315/2 "2019-07-26T23:09:51Z")

</div>

Hi there, to do this you'll need to parse your Kafka timestamp into epoch time in milliseconds. I'm not sure of the format of your timestamp so you'll need to refer to the SimpleDateFormat docs for the correct pattern to use, but here's an example of how you'd like that:

```auto
def kafka = new SimpleDateFormat('YYYY-MM-DD:HH:mm:ss.SSS').parse(doc['kafka_timestamp'].value).getTime();
def spark_process_time = doc['spark_process_time'].value;
return spark_process_time - kafka_timestamp; // Difference between the two in milliseconds

```

You don't need to convert the spark process time because that will already be in epoch time in milliseconds ([date field docs](https://www.elastic.co/guide/en/elasticsearch/reference/6.2/modules-scripting-expression.html#_date_field_api)).

See this thread for more info and a link to the SimpleDateFormat docs: [Converting a string date to a Date field using scripted fields in kibana](https://discuss.elastic.co/t/converting-a-string-date-to-a-date-field-using-scripted-fields-in-kibana/108952)

---

<div class="post-metadata">

**Author:** ![Karthik2411](https://avatars.discourse-cdn.com/v4/letter/k/ed8c4c/32.png) [@Karthik2411](https://discuss.elastic.co/u/Karthik2411)\
**Post date:** [July 26, 2019, 11:42pm UTC](https://discuss.elastic.co/t/mapping-and-scripting/192315/3 "2019-07-26T23:42:29Z")

</div>

Hello @cjcenizal. Thank you for the reply. One last question.Is it possible in kibana version 6.5??  
And if so I will try it outb and get back to you if any.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2019, 11:52pm UTC](https://discuss.elastic.co/t/mapping-and-scripting/192315/4 "2019-08-23T23:52:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
