# Please help with elapsed plugin and timestap difference

**URL:** <https://discuss.elastic.co/t/please-help-with-elapsed-plugin-and-timestap-difference/257628>\
**Category:** Elasticsearch\
**Created:** [December 4, 2020, 8:35am UTC](https://discuss.elastic.co/t/please-help-with-elapsed-plugin-and-timestap-difference/257628 "2020-12-04T08:35:30Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![fabryx87](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fabryx87/32/88165_2.png) [@fabryx87](https://discuss.elastic.co/u/fabryx87)\
**Post date:** [December 4, 2020, 8:35am UTC](https://discuss.elastic.co/t/please-help-with-elapsed-plugin-and-timestap-difference/257628/1 "2020-12-04T08:35:31Z")

</div>

Hello everyone and thanks for this great Forum!

I would need a hand with elastic, I have to make a difference between 2 timestamps that have the logonid in common, but different event.action.  
unfortunately I don't even know where to start, in ELK I'm following some trainings right now.  
To recap what I am trying to do: I am trying to get the difference between 2 timestamps for windows logon and logoff.  
I am using winlog.event\_data.TargetLogonId to track the session,  
event.action tell me if it a logon or a logoff.  
and winlog.event\_data.TargetUserName.keyword tell me the username.  
this is a script I found online and readjusted using the plugin elapsed:

```auto
    if [event.action] == "logon" {
    mutate { add_tag => ["taskStarted"] }
    } else if [event.action] == "logoff" {
    mutate { add_tag => ["taskTerminated"] }
    }
    elapsed {
    start_tag => "taskStarted"
    end_tag => "taskTerminated"
    unique_id_field => "winlog.event_data.TargetLogonId"
    timeout => 10000
    new_event_on_match => false
    add_field => "winlog.event_data.EventDuration"
    }

```

can you please help me?  
the result is to have the duration of a login session.

thanks to everyone will help me

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 8, 2020, 6:44am UTC](https://discuss.elastic.co/t/please-help-with-elapsed-plugin-and-timestap-difference/257628/2 "2020-12-08T06:44:22Z")

</div>

Doing this kind of processing in Logstash introduces a series of severe limitations in that all data had to pass through the same Logstash instance, be processed by a single thread assuming Logstash does not restart and lose state. This may work for very small use cases but scale badly.

I would therefore recommend you look at the [transform API](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/transform-apis.html) and try to use this to create a new index containing a single entity-centric document per session which you can update as data comes into Elasticsearch. With this solution you do not need to throttle your ingest processing and are likely to see much better performance.

---

<div class="post-metadata">

**Author:** ![fabryx87](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fabryx87/32/88165_2.png) [@fabryx87](https://discuss.elastic.co/u/fabryx87)\
**Post date:** [December 9, 2020, 10:28am UTC](https://discuss.elastic.co/t/please-help-with-elapsed-plugin-and-timestap-difference/257628/3 "2020-12-09T10:28:03Z")

</div>

Hi Christian,

Thanks for your reply and help.  
do you have a tutorial that can help me on it?

thanks  
Fabrizio

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 6, 2021, 10:28am UTC](https://discuss.elastic.co/t/please-help-with-elapsed-plugin-and-timestap-difference/257628/4 "2021-01-06T10:28:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
