# Add directoryname and filename as different field to elasticsearch

**URL:** <https://discuss.elastic.co/t/add-directoryname-and-filename-as-different-field-to-elasticsearch/41181>\
**Category:** Logstash\
**Created:** [February 8, 2016, 1:01pm UTC](https://discuss.elastic.co/t/add-directoryname-and-filename-as-different-field-to-elasticsearch/41181 "2016-02-08T13:01:57Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![techrawther](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@techrawther](https://discuss.elastic.co/u/techrawther)\
**Post date:** [February 8, 2016, 1:01pm UTC](https://discuss.elastic.co/t/add-directoryname-and-filename-as-different-field-to-elasticsearch/41181/1 "2016-02-08T13:01:57Z")

</div>

I am using file plugin to read mutiple files in directory . I would like to add file name and directory name as fields. how could I do that.

Following is a sample directory structure and content inside it

```
	D:/test/shahtest
		c12345/logs/linux_x64-fastdebug.log
		c12345/logs/windows_x64-fastdebug.log
		c12345/logs/windows_x64-product.log
		
		a567888/logs/linux_x64-fastdebug.log
		a567888/logs/windows_x64-fastdebug.log
		a567888/logs/windows_x64-product.log

```

Sample input

```
	input {
		file {
			path => ["D:/test/shahtest/*/logs/*.*-fastdebug.log"]		
			start_position => "beginning"
			type => "fastdebuglogs"
			add_tag => "fastdebuglogs"
			
		}
		
		file {
			path => ["D:/test/shahtest/*/logs/*.*-product.log"]		
			start_position => "beginning"
			type => "productlogs"
			add_tag => "productlogs"				
		}

```

What I am looking for is.

1. When I read one of the fastdebug file , all the event written from that file should contain directoryname and filename as different field for eg: all the event from "a567888/logs/linux\_x64-fastdebug.log" should contain field "dir\_name" as "a567888" and "file\_name" as "linux\_x64-fastdebug.log"

2. All the logs files are of each 120 Mb each so I need to grab one string "JOBID" from that specific log and add a field named JOBID with the respective value from the log. All the event happening from a specific log should have the same JOBID. I planned of using grok, but grok is event\line specific so I am not sure how could I assign this JOBID for the entire event\log from a single file.

Any help is appreciated

---

<div class="post-metadata">

**Author:** ![techrawther](https://avatars.discourse-cdn.com/v4/letter/t/41988e/32.png) [@techrawther](https://discuss.elastic.co/u/techrawther)\
**Post date:** [February 9, 2016, 4:31pm UTC](https://discuss.elastic.co/t/add-directoryname-and-filename-as-different-field-to-elasticsearch/41181/2 "2016-02-09T16:31:18Z")

</div>

I was able to do this using a grok as below.

```
        grok {
	patterns_dir => "./patterns"
	match => ["path","D:/test/shahtest/%{DATA:sjptjobid}/logs/%{DATA:sjptlogtype}.log"]
	add_tag => "pathsyslogs"
	}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:12am UTC](https://discuss.elastic.co/t/add-directoryname-and-filename-as-different-field-to-elasticsearch/41181/3 "2017-07-06T05:12:26Z")

</div>


