# Seeing if its possible to add a timeout to the sample web session detail script

**URL:** <https://discuss.elastic.co/t/seeing-if-its-possible-to-add-a-timeout-to-the-sample-web-session-detail-script/279737>\
**Category:** Elasticsearch\
**Tags:** painless\
**Created:** [July 27, 2021, 2:02pm UTC](https://discuss.elastic.co/t/seeing-if-its-possible-to-add-a-timeout-to-the-sample-web-session-detail-script/279737 "2021-07-27T14:02:45Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![jjammin92](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@jjammin92](https://discuss.elastic.co/u/jjammin92)\
**Post date:** [July 27, 2021, 2:02pm UTC](https://discuss.elastic.co/t/seeing-if-its-possible-to-add-a-timeout-to-the-sample-web-session-detail-script/279737/1 "2021-07-27T14:02:45Z")

</div>

Hello,

I've been reviewing different ways to aggregate log messages together that have a start event but no end event. Been struggling with the logstash aggregate filter plugin and was looking at retrofitting an old entity-centric model for a previous version of elasticsearch [Entity-Centric Indexing - Mark Harwood | Elastic Videos](https://www.elastic.co/videos/entity-centric-indexing-mark-harwood) when I realized elasticsearch 7.13 transforms introduce the concept of 'latest' which negates my need for a bunch of external scripts (hopefully).

I am looking at the "Getting Web Session Details by using Scripted Metric Aggregation" sample painless script, which produces session details, including session duration. Because my logs do not have an end-time, I need to make use of a timeout interval, something like a 30 minute window for aggregating message events based on my group by.

Is this possible to do within the transform by adjusting that script and could anyone help?

Thanks.

---

<div class="post-metadata">

**Author:** ![jjammin92](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@jjammin92](https://discuss.elastic.co/u/jjammin92)\
**Post date:** [July 27, 2021, 2:41pm UTC](https://discuss.elastic.co/t/seeing-if-its-possible-to-add-a-timeout-to-the-sample-web-session-detail-script/279737/2 "2021-07-27T14:41:57Z")

</div>

Hello,

I forgot to include the sample painless script that I'm trying to retrofit:

> **[Painless examples for transforms | Elasticsearch Guide \[7.13\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/transform-painless-examples.html#painless-web-session)**

I'm trying to set a timeout interval for max session duration since I do not have an end event.

---

<div class="post-metadata">

**Author:** ![jjammin92](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@jjammin92](https://discuss.elastic.co/u/jjammin92)\
**Post date:** [July 27, 2021, 5:23pm UTC](https://discuss.elastic.co/t/seeing-if-its-possible-to-add-a-timeout-to-the-sample-web-session-detail-script/279737/3 "2021-07-27T17:23:07Z")

</div>

Hello,

Just bumping this thread.

---

<div class="post-metadata">

**Author:** ![Hendrik\_Muhs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendrik_muhs/32/25802_2.png) [@Hendrik\_Muhs](https://discuss.elastic.co/u/Hendrik_Muhs)\
**Post date:** [July 28, 2021, 8:29am UTC](https://discuss.elastic.co/t/seeing-if-its-possible-to-add-a-timeout-to-the-sample-web-session-detail-script/279737/4 "2021-07-28T08:29:23Z")

</div>

We have a [feature request](https://github.com/elastic/elasticsearch/issues/54110) that sounds similar to this requirement.

Does that fit?

I don't think this is possible at the moment, even with the help of painless.

The challenge is to build the right buckets, I think this requires a new type of top-level aggregation.

---

<div class="post-metadata">

**Author:** ![jjammin92](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@jjammin92](https://discuss.elastic.co/u/jjammin92)\
**Post date:** [July 28, 2021, 4:16pm UTC](https://discuss.elastic.co/t/seeing-if-its-possible-to-add-a-timeout-to-the-sample-web-session-detail-script/279737/5 "2021-07-28T16:16:44Z")

</div>

Hello,

That's unfortunate. This a difficult problem to solve, logstash's aggregate filter plugin doesn't work to do this either.

What's the recommended way to try and solve this problem, i'm sure I'm not the only one who has tried to do this.

---

<div class="post-metadata">

**Author:** ![Hendrik\_Muhs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hendrik_muhs/32/25802_2.png) [@Hendrik\_Muhs](https://discuss.elastic.co/u/Hendrik_Muhs)\
**Post date:** [July 30, 2021, 6:22am UTC](https://discuss.elastic.co/t/seeing-if-its-possible-to-add-a-timeout-to-the-sample-web-session-detail-script/279737/6 "2021-07-30T06:22:08Z")

</div>

At the moment I can only think of solving this on the application side, e.g. adding a session id into the output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 27, 2021, 6:22am UTC](https://discuss.elastic.co/t/seeing-if-its-possible-to-add-a-timeout-to-the-sample-web-session-detail-script/279737/7 "2021-08-27T06:22:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
