# Parsing duration with 00:00:00 format

**URL:** <https://discuss.elastic.co/t/parsing-duration-with-0000-format/281284>\
**Category:** Logstash\
**Created:** [August 13, 2021, 3:40am UTC](https://discuss.elastic.co/t/parsing-duration-with-0000-format/281284 "2021-08-13T03:40:25Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sketchy](https://avatars.discourse-cdn.com/v4/letter/s/258eb7/32.png) [@Sketchy](https://discuss.elastic.co/u/Sketchy)\
**Post date:** [August 13, 2021, 3:40am UTC](https://discuss.elastic.co/t/parsing-duration-with-0000-format/281284/1 "2021-08-13T03:40:25Z")

</div>

I have a CSV that has multiple durations that are in seconds but one of the columns has the duration as 00:00:30 for 30 seconds for example. I cant work out how to get that into seconds/integer easily. I can think of a few ways, breaking it up into hours, minutes, seconds etc. I also tried using a date filter then converting the object with ruby to integer but that didn't work.

Is there an efficient way of doing this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 13, 2021, 3:58am UTC](https://discuss.elastic.co/t/parsing-duration-with-0000-format/281284/2 "2021-08-13T03:58:17Z")

</div>

> [@Sketchy](#):
>
> I can think of a few ways, breaking it up into hours, minutes, seconds etc. I also tried using a date filter then converting the object with ruby to integer but that didn't work.

Using a date filter will not work unless you diff it with 00:00:00 because there are defaults for the other fields. I would go for "breaking it up into hours, minutes, seconds". What did you try and what did not work?

---

<div class="post-metadata">

**Author:** ![zmj](https://avatars.discourse-cdn.com/v4/letter/z/87869e/32.png) [@zmj](https://discuss.elastic.co/u/zmj)\
**Post date:** [August 13, 2021, 4:12am UTC](https://discuss.elastic.co/t/parsing-duration-with-0000-format/281284/3 "2021-08-13T04:12:16Z")

</div>

TEST REPLY

---

<div class="post-metadata">

**Author:** ![zmj](https://avatars.discourse-cdn.com/v4/letter/z/87869e/32.png) [@zmj](https://discuss.elastic.co/u/zmj)\
**Post date:** [August 13, 2021, 4:13am UTC](https://discuss.elastic.co/t/parsing-duration-with-0000-format/281284/4 "2021-08-13T04:13:12Z")

</div>

TEST REPLY 2

---

<div class="post-metadata">

**Author:** ![zmj](https://avatars.discourse-cdn.com/v4/letter/z/87869e/32.png) [@zmj](https://discuss.elastic.co/u/zmj)\
**Post date:** [August 13, 2021, 4:14am UTC](https://discuss.elastic.co/t/parsing-duration-with-0000-format/281284/5 "2021-08-13T04:14:14Z")

</div>

TEST REPLY 3

---

<div class="post-metadata">

**Author:** ![Sketchy](https://avatars.discourse-cdn.com/v4/letter/s/258eb7/32.png) [@Sketchy](https://discuss.elastic.co/u/Sketchy)\
**Post date:** [August 31, 2021, 4:58am UTC](https://discuss.elastic.co/t/parsing-duration-with-0000-format/281284/6 "2021-08-31T04:58:47Z")

</div>

Hi Badger, finally got back to working on this.  
Ended up doing the below which seems to be working well.

```auto
  grok {
     match => { "ConnectedTime" => "%{NUMBER:dur_hours}:%{NUMBER:dur_mins}:%{NUMBER:dur_secs}"}
  }

 ruby {
   code => "
          h = event.get('dur_hours').to_i / 3600
          m = event.get('dur_mins').to_i / 60
          s = event.get('dur_secs').to_i
          event.set('ConnectedDuration', h + m + s).to_i
          "
 }

 mutate {
   remove_field => ["dur_hours", "dur_mins", "dur_secs"]
 }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 31, 2021, 3:00pm UTC](https://discuss.elastic.co/t/parsing-duration-with-0000-format/281284/7 "2021-08-31T15:00:34Z")

</div>

Surely "/ 3600" and "/ 60" should be "\* 3600" and "\* 60". Also, calling .to\_i on the return value of event.set does nothing, you should remove that.

Personally I would move the remove\_field into the ruby filter so that if something in those fields causes it to throw an exception those fields are not removed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 28, 2021, 3:01pm UTC](https://discuss.elastic.co/t/parsing-duration-with-0000-format/281284/8 "2021-09-28T15:01:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
