# Use timestamp from previous log line

**URL:** <https://discuss.elastic.co/t/use-timestamp-from-previous-log-line/115097>\
**Category:** Kibana\
**Created:** [January 11, 2018, 1:43pm UTC](https://discuss.elastic.co/t/use-timestamp-from-previous-log-line/115097 "2018-01-11T13:43:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tomas\_Law](https://avatars.discourse-cdn.com/v4/letter/t/b2d939/32.png) [@Tomas\_Law](https://discuss.elastic.co/u/Tomas_Law)\
**Post date:** [January 11, 2018, 1:43pm UTC](https://discuss.elastic.co/t/use-timestamp-from-previous-log-line/115097/1 "2018-01-11T13:43:09Z")

</div>

Hello,

I have several logs with a timestamp field.

I want to be able to group them by periods. That is, if the timestamp of a log is 30 minutes after the timestamp of the previous log, then it's in a different period.

For example:  
LogId Timestamp  
1 ...T08:30:00  
2 ...T08:32:15  
3 ...T09:45:01  
4 ...T09:57:09  
5 ...T13:48:11

For these logs, I want the groups (1 and 2), (3 and 4) and (5).

The condition I want to check is something like

timestamp: [previouslogtimestamp TO previouslogtimestamp+30m].

Since there is the variable "now" to use for the actual timestamp, I wonder if there's anything similar for the previous logs.

---

<div class="post-metadata">

**Author:** ![cjcenizal](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cjcenizal/32/11216_2.png) [@cjcenizal](https://discuss.elastic.co/u/cjcenizal)\
**Post date:** [January 12, 2018, 1:02am UTC](https://discuss.elastic.co/t/use-timestamp-from-previous-log-line/115097/2 "2018-01-12T01:02:25Z")

</div>

Hi Tomás, normally you'd want to use Logstash to do something like this. Unfortunately, I just checked with the Logstash team and it looks like Logstash only processes events individually (or sometimes as a batch). Either way, you can't refer to previous events the way you're asking.

However, I think you can group your events according to "time buckets". Say, grouping them by every hour. So you'd still end up with groups (1 and 2), (3 and 4), and (5). Would this help address your requirement?

Thanks,  
CJ

---

<div class="post-metadata">

**Author:** ![Tomas\_Law](https://avatars.discourse-cdn.com/v4/letter/t/b2d939/32.png) [@Tomas\_Law](https://discuss.elastic.co/u/Tomas_Law)\
**Post date:** [January 12, 2018, 10:17am UTC](https://discuss.elastic.co/t/use-timestamp-from-previous-log-line/115097/3 "2018-01-12T10:17:03Z")

</div>

Hi CJ,

Thanks for you reply. Yes, I've explored that option but it doesn't fit the requirements I want.

If I group them by pre-defined time intervals, the logs won't be grouped by sessions.  
For example, if I group them hourly:

LogId Timestamp  
1 ...T08:58:32  
2 ...T09:01:15

These 2 logs will be grouped into different sessions even though they belong to the same one ☹

The end goal is to show, for each IP address, all the LogId's separated by session.  
I have this:

ClientIP---LogId---Timestamp

1.2.3.4---1---...T08:58:32  
1.2.3.4---2---...T09:01:15

1.2.3.5---1---...T08:59:32  
1.2.3.5---2---...T09:02:15

Would it be possible to somehow create an index from the existing one?  
This way, I could:  
. Group all the events by ClientIp  
. Order by Timestamp  
. Sequentially, go through each log and store the timestamp of each log as a field SessionEnd of the aggregation  
. Therefore, I could compare the timestamp of each log to (SessionEnd+30minutes) to check whether I should group that log with the existing session or create a new session.

Thanks,  
Tomás

---

<div class="post-metadata">

**Author:** ![Andrew\_Cholakian1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_cholakian1/32/3612_2.png) [@Andrew\_Cholakian1](https://discuss.elastic.co/u/Andrew_Cholakian1)\
**Post date:** [January 12, 2018, 6:43pm UTC](https://discuss.elastic.co/t/use-timestamp-from-previous-log-line/115097/4 "2018-01-12T18:43:43Z")

</div>

> [@Tomas\_Law](#):
>
> . Therefore, I could compare the timestamp of each log to (SessionEnd+30minutes) to check whether I should group that log with the existing session or create a new session.

Your best bet would be to use the aggregate filter. [Aggregate filter plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-aggregate.html) However, that constrains you to one single threaded logstash

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2018, 6:43pm UTC](https://discuss.elastic.co/t/use-timestamp-from-previous-log-line/115097/5 "2018-02-09T18:43:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
