# Problem with elapsed plugin

**URL:** <https://discuss.elastic.co/t/problem-with-elapsed-plugin/52689>\
**Category:** Logstash\
**Created:** [June 14, 2016, 6:29am UTC](https://discuss.elastic.co/t/problem-with-elapsed-plugin/52689 "2016-06-14T06:29:55Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![zpp](https://avatars.discourse-cdn.com/v4/letter/z/54ee81/32.png) [@zpp](https://discuss.elastic.co/u/zpp)\
**Post date:** [June 14, 2016, 6:29am UTC](https://discuss.elastic.co/t/problem-with-elapsed-plugin/52689/1 "2016-06-14T06:29:55Z")

</div>

Hi,

Just hit a problem with the Elapsed plugin, referring to the data below, not sure why it reported the elapsed\_end\_without\_match error though the start event is there. I have checked that the unique\_field is the same for the start and end event.  
background:  
for this data source, the elapsed start/end events come in in sequence, so it's always like: start, end, start, end...  
patterns like start start, end, end is not possible.  
And the unique\_field used here is not really unique across different start/end pairs, i.e. the unique\_field for the current start/end pair could be the same as the previous pair.

June 13th 2016, 18:46:02.797 beats\_input\_codec\_plain\_applied, selection\_Finish, elapsed, elapsed\_match  
June 13th 2016, 18:46:02.750 beats\_input\_codec\_plain\_applied, selection\_Start  
June 13th 2016, 18:45:59.219 beats\_input\_codec\_plain\_applied, selection\_Finish, elapsed, elapsed\_match  
June 13th 2016, 18:45:59.172 beats\_input\_codec\_plain\_applied, selection\_Start  
June 13th 2016, 18:45:50.705 beats\_input\_codec\_plain\_applied, selection\_Finish, elapsed, elapsed\_match  
June 13th 2016, 18:45:50.658 beats\_input\_codec\_plain\_applied, selection\_Start  
June 13th 2016, 18:45:49.111 beats\_input\_codec\_plain\_applied, selection\_Finish, elapsed, elapsed\_match  
June 13th 2016, 18:45:49.064 beats\_input\_codec\_plain\_applied, selection\_Start  
**June 13th 2016, 18:45:47.049 beats\_input\_codec\_plain\_applied, selection\_Finish, elapsed\_end\_without\_start**  
**June 13th 2016, 18:45:47.002 beats\_input\_codec\_plain\_applied, selection\_Start**  
June 13th 2016, 18:45:46.752 beats\_input\_codec\_plain\_applied, selection\_Finish, elapsed, elapsed\_match  
June 13th 2016, 18:45:46.705 beats\_input\_codec\_plain\_applied, selection\_Start  
June 13th 2016, 18:45:38.315 beats\_input\_codec\_plain\_applied, selection\_Finish, elapsed, elapsed\_match  
June 13th 2016, 18:45:38.268 beats\_input\_codec\_plain\_applied, selection\_Start  
June 13th 2016, 18:45:37.050 beats\_input\_codec\_plain\_applied, selection\_Finish, elapsed, elapsed\_match  
June 13th 2016, 18:45:37.003 beats\_input\_codec\_plain\_applied, selection\_Start

Thank you!

---

<div class="post-metadata">

**Author:** ![zpp](https://avatars.discourse-cdn.com/v4/letter/z/54ee81/32.png) [@zpp](https://discuss.elastic.co/u/zpp)\
**Post date:** [June 14, 2016, 6:59am UTC](https://discuss.elastic.co/t/problem-with-elapsed-plugin/52689/2 "2016-06-14T06:59:34Z")

</div>

I configured multiple hosts in the elasticsearch output plugin hosts option, could this be the cause?  
In logstash document, it stats **\> If given an array it will load balance requests across the hosts specified in the hosts parameter.** , how does this load balance work? periodically switching among the hosts, or randomly pick on host and stick to it, switch only if problem happens?

---

<div class="post-metadata">

**Author:** ![pantheo](https://avatars.discourse-cdn.com/v4/letter/p/9de0a6/32.png) [@pantheo](https://discuss.elastic.co/u/pantheo)\
**Post date:** [June 22, 2016, 9:03am UTC](https://discuss.elastic.co/t/problem-with-elapsed-plugin/52689/3 "2016-06-22T09:03:01Z")

</div>

I do not think that multiple hosts are the problem. I am using the elapsed filter plugin with a single elasticsearch node and have noticed the same problem as you.

While it works, for the majority of time, sometimes I get an elapsed\_end\_without\_start tag even though the start event is present.

One more problem I noticed is that if I do not add the **periodic\_flush** setting the **timeout** setting never kicks in.

The event is never marked as expired and therefore no **elapsed\_expired\_error** tag is generated (unless I add the **periodic\_flush** setting as mentioned above.

Is this a bug or the way it should works? I am asking because the **periodic\_flush** setting is marked as optional.

---

<div class="post-metadata">

**Author:** ![zpp](https://avatars.discourse-cdn.com/v4/letter/z/54ee81/32.png) [@zpp](https://discuss.elastic.co/u/zpp)\
**Post date:** [July 1, 2016, 3:02am UTC](https://discuss.elastic.co/t/problem-with-elapsed-plugin/52689/4 "2016-07-01T03:02:28Z")

</div>

pantheo, you're right, the problem persists even we changed the configuration to one server only rather than load balancing.  
Can someone enlighten us on this problem? It's a big problem to us as we use this plugin quite extensively.

---

<div class="post-metadata">

**Author:** ![pantheo](https://avatars.discourse-cdn.com/v4/letter/p/9de0a6/32.png) [@pantheo](https://discuss.elastic.co/u/pantheo)\
**Post date:** [July 4, 2016, 7:52am UTC](https://discuss.elastic.co/t/problem-with-elapsed-plugin/52689/5 "2016-07-04T07:52:34Z")

</div>

Zpp, judging from the plugin's discussion section in github, I do not think we will get an answer any time soon.  
However, I have overcome this problem, short of, by incorporating the **elapsed\_end\_without\_start** tag to what I am doing with the **elapsed\_match** tag.  
For example, I have actions that some may end and others may not. **Every action** though has a Request Begin section, just like in your example. What I am doing with the elapsed plugin is to check whether an action has a matching Request End section.  
Well I am considering actions that also have the **elapsed\_end\_without\_start** tag along with the ones with the **elapsed\_match** tag in my visualizations.  
It is not perfect, but for now it gets the job done.

---

<div class="post-metadata">

**Author:** ![zpp](https://avatars.discourse-cdn.com/v4/letter/z/54ee81/32.png) [@zpp](https://discuss.elastic.co/u/zpp)\
**Post date:** [July 7, 2016, 8:28am UTC](https://discuss.elastic.co/t/problem-with-elapsed-plugin/52689/6 "2016-07-07T08:28:22Z")

</div>

hi pantheo, thanks for sharing. I changed the indexer startup parameter (-w 1) to force indexer to only use single thread for filtering and output. This will slow down the indexing rate, but solves my problem.

---

<div class="post-metadata">

**Author:** ![pantheo](https://avatars.discourse-cdn.com/v4/letter/p/9de0a6/32.png) [@pantheo](https://discuss.elastic.co/u/pantheo)\
**Post date:** [July 11, 2016, 1:52pm UTC](https://discuss.elastic.co/t/problem-with-elapsed-plugin/52689/7 "2016-07-11T13:52:20Z")

</div>

Hi Zpp,

thanks for sharing your solution. I will try it to our infrastructure too and see if the problem solves.

Regards

---

<div class="post-metadata">

**Author:** ![jpfcruz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jpfcruz/32/15742_2.png) [@jpfcruz](https://discuss.elastic.co/u/jpfcruz)\
**Post date:** [February 21, 2017, 4:12pm UTC](https://discuss.elastic.co/t/problem-with-elapsed-plugin/52689/8 "2017-02-21T16:12:29Z")

</div>

Hi all,

Just to let you now that today I came across this very same problem. After following the recommendation to configure the workers number to "1" (and, thus, do not multithread the processing) everything went fine.

A source with almost 1 million request-response pairs: With 2 workers, around 10k requests didn't get its elapsed time calculated. With a single worker all of them were OK.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:28am UTC](https://discuss.elastic.co/t/problem-with-elapsed-plugin/52689/9 "2017-07-06T04:28:23Z")

</div>


