# Tabular form or report based on logs

**URL:** https://discuss.elastic.co/t/tabular-form-or-report-based-on-logs/380684
**Category:** Elasticsearch
**Created:** [August 2, 2025, 4:08am UTC](https://discuss.elastic.co/t/tabular-form-or-report-based-on-logs/380684 "2025-08-02T04:08:29Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![dsrini-open](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsrini-open/32/144444_2.png) [@dsrini-open](https://discuss.elastic.co/u/dsrini-open)
#### Post date: [August 2, 2025, 4:08am UTC](https://discuss.elastic.co/t/tabular-form-or-report-based-on-logs/380684/1 "2025-08-02T04:08:29Z")

</div>

I have the following logs -

> 20:00:00 Started processing  
> 20:05:00 Successfully finished  
> 20:05:03 Output file - /temp/file2  
> 20:05:03 Started processing  
> 20:10:10 Successfully finished  
> 20:10:14 Output file - /temp/file34  
> 20:10:15 Started processing  
> 20:15:00 Successfully finished  
> 20:15:03 Output file - /temp/file16

And, I need a report of the form

Start Finish Output file  
20:00:00 20:05:00 /temp/file2  
20:05:03 20:10:10 /temp/file34  
20:10:15 20:15:00 /temp/file16

Is there a way to generate in ESS or kibana using the KQL or ESQL ? Appreciate any idea or help

---

<div class="post-metadata">

### Author: ![Tortoise](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tortoise/32/147587_2.png) [@Tortoise](https://discuss.elastic.co/u/Tortoise)
#### Post date: [August 2, 2025, 5:39am UTC](https://discuss.elastic.co/t/tabular-form-or-report-based-on-logs/380684/2 "2025-08-02T05:39:56Z")

</div>

Hello @dsrini-open

Welcome to the community!!

I understand your requirement but currently you are following record by record approach considering every 3 records, right? How do we know if it is for the same record , is there any common id which will distinguish the start-end-outputfile from others?

Example in your record i use unique id

```auto
id=1 20:00:00 Started processing
id=1 20:05:00 Successfully finished
id=1 20:05:03 Output file - /temp/file2

```

than

```auto
id=2 20:05:03 Started processing
id=2 20:10:10 Successfully finished
id=2 20:10:14 Output file - /temp/file34

```

Incase you have any common id like used in above records than Using ES|QL :

```auto
FROM 02aug-req
| STATS
    start_time = MIN(CASE(message LIKE "*Started*", time)),
    end_time = MIN(CASE(message LIKE "*finished*", time)),
    output_file = MIN(CASE(message LIKE "*file*", message))
    BY id
| WHERE start_time IS NOT NULL AND end_time IS NOT NULL AND output_file IS NOT NULL
| KEEP start_time, end_time, output_file
| SORT start_time ASC

```

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/e/2e9e1306ef55c7c90080b7ed5ff6ba5dd61aae28.png)

Thanks!!

---

<div class="post-metadata">

### Author: ![dsrini-open](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsrini-open/32/144444_2.png) [@dsrini-open](https://discuss.elastic.co/u/dsrini-open)
#### Post date: [August 3, 2025, 1:24am UTC](https://discuss.elastic.co/t/tabular-form-or-report-based-on-logs/380684/3 "2025-08-03T01:24:40Z")

</div>

Wow, Thanks. We are not currently logging the ID. Let me see if that can be done so that the stats are easier to obtain. Appreciate your help.
