# Subtracting two values of a field

**URL:** <https://discuss.elastic.co/t/subtracting-two-values-of-a-field/306915>\
**Category:** Logstash\
**Created:** [June 10, 2022, 8:58pm UTC](https://discuss.elastic.co/t/subtracting-two-values-of-a-field/306915 "2022-06-10T20:58:18Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![zaeemmasood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zaeemmasood/32/102383_2.png) [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Post date:** [June 10, 2022, 8:58pm UTC](https://discuss.elastic.co/t/subtracting-two-values-of-a-field/306915/1 "2022-06-10T20:58:18Z")

</div>

Hello All,

I have a set up which parses the following line in a log file:

```auto
[2022-06-10T19:52:05.017+0000][info][gc] GC(35959) Pause Full (Diagnostic Command) 1850M->1140M(2560M) 506.831ms

```

The resultant gets displayed in Kibana as follows. See excerpt:

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/3/039868bda1e3a8944015dbbf90aec60bf25d76df.png)

I need to subtract the heapDrop values i.e. `1850 -> 1140` and store the resultant in a different field which I could use to create charts from.

My config looks like below:

```auto
          if [type] == "tv_gclog_analysis" {

                        if "start" in [message] { drop{} }
                        if "Full" in [message] {
                                grok {
                                        match => { "message" => '\[%{TIMESTAMP_ISO8601:createdTime}\]\[%{WORD:logLevel}\]+%{GREEDYDATA:message} %{GREEDYDATA:heapDrop}\(%{DATA:maxHeap:int}\) %{GREEDYDATA:timeTaken:float}' }
                        }

                                }
                        else {
                               drop {}
                            }
                        }
                }

```

Please guide. Do I need to use a ruby filter to make this happen?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 10, 2022, 10:25pm UTC](https://discuss.elastic.co/t/subtracting-two-values-of-a-field/306915/2 "2022-06-10T22:25:24Z")

</div>

If you have the bytes filter installed (it is not bundled by default) you could use

```
    grok { match => { "heapDrop" => "%{WORD:upper}->%{WORD:lower}" } }
    mutate { replace => { "upper" => "%{upper}B" "lower" => "%{lower}B" } }
    bytes { source => "upper" target => "upper" }
    bytes { source => "lower" target => "lower" }
    ruby { code => 'event.set("delta", event.get("upper").gsub("M", "000000").gsub("G", "000000000").gsub - event.get("lower"))' }

```

If you cannot or do not want to install it then

```
    grok { match => { "heapDrop" => "%{WORD:upper}->%{WORD:lower}" } }
    ruby {
        code => '
            lower = event.get("lower")
            upper = event.get("upper")
            if lower and upper
                lower = lower.gsub("M", "000000").gsub("G", "000000000").gsub("T", "000000000000").to_i
                upper = upper.gsub("M", "000000").gsub("G", "000000000").gsub("T", "000000000000").to_i
                event.set("delta", upper - lower)
            end
        '
    }

```

but there is a big difference between 710000000 and 744488960.

---

<div class="post-metadata">

**Author:** ![zaeemmasood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zaeemmasood/32/102383_2.png) [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Post date:** [June 11, 2022, 3:15am UTC](https://discuss.elastic.co/t/subtracting-two-values-of-a-field/306915/3 "2022-06-11T03:15:19Z")

</div>

> [@Badger](#):
>
> but there is a big difference between 710000000 and 744488960

Hi Badger. Sorry couldn't get this part.

Also I will have to go for the second option as the servers are not open to internet.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 11, 2022, 3:23am UTC](https://discuss.elastic.co/t/subtracting-two-values-of-a-field/306915/4 "2022-06-11T03:23:45Z")

</div>

> [@zaeemmasood](#):
>
> Sorry couldn't get this part.

The bytes filter will convert 1 MB to 1024x1024. The gsub will convert 1 MB to 1000x1000. I am saying that those small errors add up surprisingly quickly. The difference is between 710 million bytes and 744 million bytes.

Depending on your use case this may or may not matter. If you are aggregating the volume of garbage collected over an interval then the difference between 710 million and 744 million may be negligible, whereas if you collect 2 GB of garbage in one hour, and 75 GB of garbage in the next, that may tell you something.

---

<div class="post-metadata">

**Author:** ![zaeemmasood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zaeemmasood/32/102383_2.png) [@zaeemmasood](https://discuss.elastic.co/u/zaeemmasood)\
**Post date:** [June 16, 2022, 8:36pm UTC](https://discuss.elastic.co/t/subtracting-two-values-of-a-field/306915/5 "2022-06-16T20:36:41Z")

</div>

Thanks @Badger as always!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2022, 8:37pm UTC](https://discuss.elastic.co/t/subtracting-two-values-of-a-field/306915/6 "2022-07-14T20:37:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
