# Some problem of logstash elapsed filter

**URL:** <https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111>\
**Category:** Logstash\
**Created:** [November 26, 2018, 2:56am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111 "2018-11-26T02:56:57Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![zxc654951](https://avatars.discourse-cdn.com/v4/letter/z/c89c15/32.png) [@zxc654951](https://discuss.elastic.co/u/zxc654951)\
**Post date:** [November 26, 2018, 2:56am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/1 "2018-11-26T02:56:57Z")

</div>

![ELAPSED%20PROBLEM](https://us1.discourse-cdn.com/elastic/original/3X/a/a/aa9326ba5cb3fa4eac91f81956f9371e692f639c.png)

I use elapsed filter to calculate events duration, but it has something wrong. The elapsed\_time got negative number in my case.

config below:

 ![ELAPSED%20CONFIG](https://us1.discourse-cdn.com/elastic/original/3X/d/7/d717eb6d938bfb458ae8b742758f26dd0943fe4a.png)

Can someone help me?  
Thanks.

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 26, 2018, 9:04am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/2 "2018-11-26T09:04:08Z")

</div>

Your start and end events coming in very quickly, 100ms from each other is that correct?

---

<div class="post-metadata">

**Author:** ![zxc654951](https://avatars.discourse-cdn.com/v4/letter/z/c89c15/32.png) [@zxc654951](https://discuss.elastic.co/u/zxc654951)\
**Post date:** [November 26, 2018, 10:44am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/3 "2018-11-26T10:44:30Z")

</div>

Thanks for your reply first. I got a search result for elpased\_time between 0 to 1, like below pic.

 ![ELAPSED%20PROBLEM2](https://us1.discourse-cdn.com/elastic/original/3X/1/1/116e6f6767b37a71d9a591499c3721eb20579ba1.png)

Sometime elapsed get work when events between 100ms. But it maybe duration of events too fast to got this problem. And, I want to let it become normally to work correct. Hope for more discuss. Thanks.

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 26, 2018, 10:52am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/4 "2018-11-26T10:52:03Z")

</div>

Correct I think possibly the events are too fast

---

<div class="post-metadata">

**Author:** ![zxc654951](https://avatars.discourse-cdn.com/v4/letter/z/c89c15/32.png) [@zxc654951](https://discuss.elastic.co/u/zxc654951)\
**Post date:** [November 26, 2018, 11:29am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/5 "2018-11-26T11:29:41Z")

</div>

Have other solution？I want to use elapsed to do performance report.

---

<div class="post-metadata">

**Author:** ![Eniqmatic](https://avatars.discourse-cdn.com/v4/letter/e/ea5d25/32.png) [@Eniqmatic](https://discuss.elastic.co/u/Eniqmatic)\
**Post date:** [November 26, 2018, 11:39am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/6 "2018-11-26T11:39:07Z")

</div>

I am unsure, perhaps raise a bug on github with the logstash team?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 26, 2018, 11:40am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/7 "2018-11-26T11:40:43Z")

</div>

How many worker threads do you have configured for Logstash?

---

<div class="post-metadata">

**Author:** ![zxc654951](https://avatars.discourse-cdn.com/v4/letter/z/c89c15/32.png) [@zxc654951](https://discuss.elastic.co/u/zxc654951)\
**Post date:** [November 26, 2018, 2:11pm UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/8 "2018-11-26T14:11:47Z")

</div>

It has default setting, but I think it have 4 threads.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 26, 2018, 3:21pm UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/9 "2018-11-26T15:21:22Z")

</div>

If I recall correctly, one of the major drawbacks with the elapsed and aggregate filters is that all related events have to pass through the same processing thread, thereby limiting Logstash to a single worker thread and instance. This naturally severely limits throughput and scales very badly. Try setting the number of worker threads to 1 to see if it resolves the accuracy issue.

A more scalable approach may be to have a periodic batch job that post-process events once they are in Elasticsearch, but although this is likely to scale better it does introduce a delay.

---

<div class="post-metadata">

**Author:** ![zxc654951](https://avatars.discourse-cdn.com/v4/letter/z/c89c15/32.png) [@zxc654951](https://discuss.elastic.co/u/zxc654951)\
**Post date:** [November 27, 2018, 8:23am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/10 "2018-11-27T08:23:54Z")

</div>

There are some wrong elapsed time after change the thread to 1 worker. Changing thread maybe let it work, but still have some wrong elapsed.

 ![logstash%20yml](https://us1.discourse-cdn.com/elastic/original/3X/9/9/99ba922db75635d73d58f54a3369a1b0feedbd56.png)  
 ![ELAPSED%20PROBLEM3](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b93934e0c652ff66802acf750bee716bdddb3109.png)

Ooes pipeline.batch.size and pipeline.batch.delay have to change?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 27, 2018, 8:29am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/11 "2018-11-27T08:29:48Z")

</div>

What does the underlying events that contributed to an incorrect elapsed time look like if you view them in Kibana?

---

<div class="post-metadata">

**Author:** ![zxc654951](https://avatars.discourse-cdn.com/v4/letter/z/c89c15/32.png) [@zxc654951](https://discuss.elastic.co/u/zxc654951)\
**Post date:** [November 27, 2018, 8:49am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/12 "2018-11-27T08:49:05Z")

</div>

I take a few events picture. Its tag seem like missing start\_tag.

 ![ELAPSED%20PROBLEM4](https://us1.discourse-cdn.com/elastic/original/3X/d/c/dc4d4a8d81c981db668ce06012a495aa331a78cb.png)

Do my elapsed code wrong in logstash.conf? Doesn't have to use `else if`?

---

<div class="post-metadata">

**Author:** ![zxc654951](https://avatars.discourse-cdn.com/v4/letter/z/c89c15/32.png) [@zxc654951](https://discuss.elastic.co/u/zxc654951)\
**Post date:** [November 30, 2018, 2:19am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/13 "2018-11-30T02:19:58Z")

</div>

Hello, who can tell me where is going wrong?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 28, 2018, 2:20am UTC](https://discuss.elastic.co/t/some-problem-of-logstash-elapsed-filter/158111/14 "2018-12-28T02:20:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
