# Pipeline computed Field

**URL:** <https://discuss.elastic.co/t/pipeline-computed-field/266558>\
**Category:** Kibana\
**Created:** [March 8, 2021, 1:08pm UTC](https://discuss.elastic.co/t/pipeline-computed-field/266558 "2021-03-08T13:08:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![graimato](https://avatars.discourse-cdn.com/v4/letter/g/9e8a1a/32.png) [@graimato](https://discuss.elastic.co/u/graimato)\
**Post date:** [March 8, 2021, 1:08pm UTC](https://discuss.elastic.co/t/pipeline-computed-field/266558/1 "2021-03-08T13:08:53Z")

</div>

Hello,  
I wrote a pipeline to parse log files, I'm trying to create a computed field I have es.

- timerequest
- timeresponse

It is possible to create a new field latency

```auto
  {
        "set" : {
          "field" : "latency",
          "value" : "{{timeresponse - timerequest}}"
      }
    },
      {
        "convert" : {
          "field" : "latency",
          "type" : "float",
          "on_failure" : [
            {
              "set" : {
                "field" : "latency",
                "value" : -1
              }
            }
          ]
        }
      }

```

I do not want to use Enrich pipeline, I need a simple difference between fields

Is it possible?

best regards

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [March 8, 2021, 4:41pm UTC](https://discuss.elastic.co/t/pipeline-computed-field/266558/2 "2021-03-08T16:41:50Z")

</div>

Yes absolutely you just need to get the syntax correct

Assuming the one you are taking about is the latency it should look something like this you would use the [painless scripting language](https://www.elastic.co/guide/en/elasticsearch/painless/current/painless-walkthrough.html).

You might need to guard it

```
{
 "if": "ctx.timeresponse != null && ctx.timerequest != null",
  "script": {
    "lang": "painless",
    "source": "ctx.latency = ctx.timeresponse - ctx.timerequest",
  }
}
```

---

<div class="post-metadata">

**Author:** ![graimato](https://avatars.discourse-cdn.com/v4/letter/g/9e8a1a/32.png) [@graimato](https://discuss.elastic.co/u/graimato)\
**Post date:** [March 9, 2021, 8:18am UTC](https://discuss.elastic.co/t/pipeline-computed-field/266558/3 "2021-03-09T08:18:28Z")

</div>

@stephenb  
Thanks so much It works.  
best regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 6, 2021, 8:18am UTC](https://discuss.elastic.co/t/pipeline-computed-field/266558/4 "2021-04-06T08:18:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
