# Measuring multiple event durations with elapsed plugin

**URL:** https://discuss.elastic.co/t/measuring-multiple-event-durations-with-elapsed-plugin/107809
**Category:** Logstash
**Created:** [November 15, 2017, 7:09pm UTC](https://discuss.elastic.co/t/measuring-multiple-event-durations-with-elapsed-plugin/107809 "2017-11-15T19:09:24Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![joconner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joconner/32/24360_2.png) [@joconner](https://discuss.elastic.co/u/joconner)
#### Post date: [November 15, 2017, 7:09pm UTC](https://discuss.elastic.co/t/measuring-multiple-event-durations-with-elapsed-plugin/107809/1 "2017-11-15T19:09:24Z")

</div>

My event stream log items look like this:  
`<timestamp>, <event_id>, <resource_id>, <resource_type>`

My event\_id fields can be several strings that look like this:

- FOO\_BEGIN
- FOO\_END
- BAR\_BEGIN
- BAR\_END
- BUZZ\_BEGIN
- BUZZ\_END

For any particular `resource_id`, I have multiple BEGIN/END pairs for various workflow events on a resource.

Since the `elapsed` plugin uses tags, not events, I also have a `mutate` filter that adds the FOO\_BEGIN/FOO\_END, BAR\_BEGIN/BAR\_END event names as tags to those logged items. I'm planning to use these tag names in the `elapsed` blocks and use the the literal string "resource\_id" in the `unique_id_field` like this:

```auto
elapsed {
    start_tag => "FOO_BEGIN"
    end_tag => "FOO_END"
    unique_id_field => "resource_id"
    timeout => 600
}

```

My questions:

1. If I want to measure the elapsed time between several BEGIN/END pairs, do I have to create a separate `elapsed` logstash item for each? That is, do I need a separate`elapsed` structure for each event pair: FOO, BAR, BUZZ? Or can I create a single `elapsed` block that has a variable `start_tag` and `end_tag` value? Something like this maybe:

```auto
elapsed {
    start_tag => "%{SOMEVARIABLE}_BEGIN"
    end_tag => "%{SOMEVARIABLE}_END"
    unique_id_field => "resource_id"
    timeout => 600
}

```

1. Is it ok that the `elapsed` blocks are outside any `if` block and executed even on events that are _not_ the targets? Or do I need to put these `elapsed` blocks within an `if` structure to isolate them just for those events?

Thanks for your help.

---

<div class="post-metadata">

### Author: ![joconner](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joconner/32/24360_2.png) [@joconner](https://discuss.elastic.co/u/joconner)
#### Post date: [November 17, 2017, 1:04am UTC](https://discuss.elastic.co/t/measuring-multiple-event-durations-with-elapsed-plugin/107809/2 "2017-11-17T01:04:34Z")

</div>

I tried using a single `elapsed` structure with variables in the `start_tag` and `end_tag` fields. This failed miserably. Since I need to track ~20 different begin/end pairs, I've had to create 20 specific `elapsed` blocks to handle each one separately. The variable syntax within an `elapsed` block doesn't appear to work as planned.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 15, 2017, 1:04am UTC](https://discuss.elastic.co/t/measuring-multiple-event-durations-with-elapsed-plugin/107809/3 "2017-12-15T01:04:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
