# Adding a type field dynamically for logs

**URL:** <https://discuss.elastic.co/t/adding-a-type-field-dynamically-for-logs/73883>\
**Category:** Logstash\
**Created:** [February 3, 2017, 4:41pm UTC](https://discuss.elastic.co/t/adding-a-type-field-dynamically-for-logs/73883 "2017-02-03T16:41:12Z")\
**Posts on this page:** 1\
**Showing post:** 9

<div class="post-metadata">

**Author:** ![Maria\_Delarosa](https://avatars.discourse-cdn.com/v4/letter/m/87869e/32.png) [@Maria\_Delarosa](https://discuss.elastic.co/u/Maria_Delarosa)\
**Post date:** [February 9, 2017, 8:27pm UTC](https://discuss.elastic.co/t/adding-a-type-field-dynamically-for-logs/73883/9 "2017-02-09T20:27:06Z")

</div>

Great! Below is my final code. I decided for any logs under a sub-directory to determine the `type` based on that directory name. For example `/var/log/logsfrommanyapps/app1/app1-test.log` is of `type => app1` (using the grok filter that you show in your first response). Then for any logs in the base directory, I am using the name of the log file. E.g. `/var/log/logsfrommanyapps/test.log` is of `type => test` as you show above. However, there is an issue in displaying the `type` for logs under a sub-directory. For `/var/log/logsfrommanyapps/app1/app1-test.log` it shows as `type => app1/app1-test` instead of `type => app1`.

**Edit** : to avoid any further problems for any logs under a subdirectory, is it possible to just give it the second level directory name to `type`. For example `/var/log/logsfrommanyapps/app1/anotherdirectory/app1-test.log` will give `type => app1`.

```
input{
    file {
            path => ["/var/log/logsfrommanyapps/*/*.log"]
            ignore_older => 7776000
            start_position => "beginning"
            sincedb_path => "/dev/null"
    }
    file {
            path => ["/var/log/logsfrommanyapps/*.log"]
            ignore_older => 7776000
            start_position => "beginning"
            sincedb_path => "/dev/null"
    }
    filter {
       grok {
              match => { "path" => [
                  "^/var/log/logsfrommanyapps/%{WORD:type}/%{DATA}$" 
                  "^/var/log/logsfrommanyapps/%{NOTSPACE:type}.log$" 
           ]}
          overwrite => ["type"]
       }
    }
	output {
		stdout { codec => rubydebug { metadata => true } }
	}
}
```

---

_[View the full topic](https://discuss.elastic.co/t/adding-a-type-field-dynamically-for-logs/73883)._
