# What is the last\_time field supposed to represent?

**URL:** <https://discuss.elastic.co/t/what-is-the-last-time-field-supposed-to-represent/96644>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [August 10, 2017, 4:26pm UTC](https://discuss.elastic.co/t/what-is-the-last-time-field-supposed-to-represent/96644 "2017-08-10T16:26:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![wmathews](https://avatars.discourse-cdn.com/v4/letter/w/76d3ee/32.png) [@wmathews](https://discuss.elastic.co/u/wmathews)\
**Post date:** [August 10, 2017, 4:26pm UTC](https://discuss.elastic.co/t/what-is-the-last-time-field-supposed-to-represent/96644/1 "2017-08-10T16:26:15Z")

</div>

The documentation says "The time, the most recent processed packet for the flow has been seen.", however for all of the entries in my cluster, this is always exactly the same as the start\_time field even when the flow was open for multiple time periods and new packets were received after the first.

```
{
  "_index": "packetbeat-2017.05.17",
  "_type": "flow",
  "_id": "AVwWWIfwxpQtYgsqMToo",
  "_score": null,
  "_source": {
    "@timestamp": "2017-05-17T12:18:40.000Z",
    "beat": {
      ...
    },
    "dest": {
     ...
      "stats": {
        "net_bytes_total": 3505,
        "net_packets_total": 13
      }
    },
    "final": false,
    "flow_id": "EQQA////DP//////FP8BAAH6Fj5/r7b6Fj66+u/AqB0UwKgKA48Az4c",
    "last_time": "2017-05-17T12:18:18.691Z",
    "source": {
      ...
      "stats": {
        "net_bytes_total": 1821,
        "net_packets_total": 13
      }
    },
    "start_time": "2017-05-17T12:18:18.691Z",
    "transport": "tcp",
    "type": "flow"
  },
  "fields": {
    "start_time": [
      1495023498691
    ],
    "@timestamp": [
      1495023520000
    ],
    "last_time": [
      1495023498691
    ]
  },
  "sort": [
    1495023520000
  ]
}

{
  "_index": "packetbeat-2017.05.17",
  "_type": "flow",
  "_id": "AVwWWK8AxpQtYgsqMTph",
  "_score": null,
  "_source": {
    "@timestamp": "2017-05-17T12:18:50.000Z",
    "beat": {
      ...
    },
    "dest": {
      ...
      "stats": {
        "net_bytes_total": 4509,
        "net_packets_total": 17
      }
    },
    "final": false,
    "flow_id": "EQQA////DP//////FP8BAAH6Fj5/r7b6Fj66+u/AqB0UwKgKA48Az4c",
    "last_time": "2017-05-17T12:18:18.691Z",
    "source": {
      ...
      "stats": {
        "net_bytes_total": 2589,
        "net_packets_total": 19
      }
    },
    "start_time": "2017-05-17T12:18:18.691Z",
    "transport": "tcp",
    "type": "flow"
  },
  "fields": {
    "start_time": [
      1495023498691
    ],
    "@timestamp": [
      1495023530000
    ],
    "last_time": [
      1495023498691
    ]
  },
  "sort": [
    1495023530000
  ]
}

```

Here you can see two separate entries from Packetbeat describing the same long running flow, where new packets are seen in the second entry but the last\_time field is never updated, and always remains the same as the start\_time field.

Should it not be updating every time a new packet is received? Is this a bug of some sort? Has anyone ever had this field work for them? I am trying to do work that requires this information so if I can't get this to work I'll need to use a different solution, which would be unfortunate since Packetbeat does what I need it to otherwise.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 11, 2017, 1:54pm UTC](https://discuss.elastic.co/t/what-is-the-last-time-field-supposed-to-represent/96644/2 "2017-08-11T13:54:32Z")

</div>

I'd say this is a bug. Can you report this [on github](https://github.com/elastic/beats/issues) please?

---

<div class="post-metadata">

**Author:** ![wmathews](https://avatars.discourse-cdn.com/v4/letter/w/76d3ee/32.png) [@wmathews](https://discuss.elastic.co/u/wmathews)\
**Post date:** [August 15, 2017, 4:10pm UTC](https://discuss.elastic.co/t/what-is-the-last-time-field-supposed-to-represent/96644/3 "2017-08-15T16:10:38Z")

</div>

Okay, I made a topic. I wasn't sure how to add labels though

> <https://github.com/elastic/beats/issues/4895>

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [August 15, 2017, 7:53pm UTC](https://discuss.elastic.co/t/what-is-the-last-time-field-supposed-to-represent/96644/4 "2017-08-15T19:53:59Z")

</div>

Thanks for reporting the issue. I added the labels. Seems all packetbeat versions are affected ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 12, 2017, 7:54pm UTC](https://discuss.elastic.co/t/what-is-the-last-time-field-supposed-to-represent/96644/5 "2017-09-12T19:54:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
