# Apply grok pattern based on the log file path

**URL:** <https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395>\
**Category:** Logstash\
**Created:** [May 26, 2023, 6:10am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395 "2023-05-26T06:10:46Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [May 26, 2023, 6:10am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/1 "2023-05-26T06:10:46Z")

</div>

Hi Here is my logstash config file

```auto
input {
  beats {
    port => 5044
  }
}
output {
  elasticsearch {
    hosts => "http://ip:9200"
    index => "%{type}-%{+YYYY.MM.dd}"
    user => "elastic"
    password => "pwd"
  }
}

```

I have logs coming from multiple sources using this pipeline. I want to apply grok on file coming from only one source and no pattern at all for others. The files coming from the source on which i want to grok are coming from multiple paths.  
So if the log file path consists of "Apache" i want to apply one grok and if it consists of another string i want to apply one grok. and no grok for others. How can that be done?

I Tried adding tag in filebeat config

```auto
- type: log
  enabled: true
  paths:
    - 'D:\3DS-apache\Apache\Apache24\logs\3dx_access.log'
  fields:
    type: 3dxp_apachetrace
    3dxp_tag: 3dxp_apache
  fields_under_root: true
- type: log
  enabled: true
  paths:
    - 'path1*'
  fields:
    type: 3dxp_servicetrace
    3dxp_tag: 3dxp_service
  fields_under_root: true

```

In the logs there is a field called 3dxp\_tag

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/3/33013c1f0c7eb21076526a1b774c7fd7804c18b2.png)

But when i try to use the 3dxp\_tag in logstash config nothing seems to work, by default the first grok is getting applied  
Here is logstash config

```auto
input {
  beats {
    port => 5044
  }
}
filter {
  if [3dxp_tag] == "3dxp_apache"
  {
      grok {
        match => { "message" => ["\[%{HTTPDATE:timestamp}\] \| %{NUMBER:response} \| (?<duration>%{NUMBER} %{WORD}) \| (?<bytes>%{NUMBER} %{WORD}|%{DATA}) \| %{IP:hostip} \| (%{IP:clientip}|%{DATA:clientip}) \| (%{WORD:token}|%{DATA:token}) \| (?<tag1>%{NUMBER} %{WORD}|%{DATA}) \| \"(?<method>%{WORD}) (?<url>%{URIPATHPARAM}) (?:HTTP/%{NUMBER:http_version})\""] }
    }
  }
  else if [3dxp_tag] == "3dxp_service"
  {
      grok {
        match => { "message" => ["\[%{HTTPDATE:timestamp}\] \| %{NUMBER:response} \| (?<duration>%{NUMBER} %{WORD}) \| (?<bytes>%{NUMBER} %{WORD}|%{DATA}) \| %{IP:hostip} \| (%{DATA:clientip}|%{IP:clientip}) \| (%{WORD:token}|%{DATA:token}) \| (?<tag1>%{NUMBER} %{WORD}|%{DATA}) \| \"(?<method>%{WORD}) (?<url>%{URIPATHPARAM}) (?:HTTP/%{NUMBER:http_version})\" \| (%{EMAILADDRESS:loginemail}|%{DATA:loginemail})"] }
    }

  }
}
output {
  elasticsearch {
    hosts => "http://ip:9200"
    index => "%{type}-%{+YYYY.MM.dd}"
    user => "elastic"
    password => "pwd"
  }
}

```

There is a difference of only one field in both groks, but the second grok isnt getting applied

---

<div class="post-metadata">

**Author:** ![Anton\_H](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anton_h/32/10200_2.png) [@Anton\_H](https://discuss.elastic.co/u/Anton_H)\
**Post date:** [May 29, 2023, 7:57pm UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/2 "2023-05-29T19:57:48Z")

</div>

Hi @Neelam_Zanvar do you have any events in elastic with the value 3dxp\_service?  
Even if the grok didn't work, you should still have an event with the tag field and a message field containing the entire message, because it couldn't get parsed...

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 29, 2023, 8:33pm UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/3 "2023-05-29T20:33:16Z")

</div>

```auto
- type: log
  enabled: true
  paths:
    - 'path1*' <!---- THAT DOES NOT LOOK RIGHT
  fields:
    type: 3dxp_servicetrace
    3dxp_tag: 3dxp_service
  fields_under_root: true

```

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [May 31, 2023, 4:39am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/4 "2023-05-31T04:39:37Z")

</div>

No i don't have any event in elastic. I didn't really get your question. THe config i shared are the only configurations i have made

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [May 31, 2023, 4:40am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/5 "2023-05-31T04:40:13Z")

</div>

But it is taking all the files from that path after i added \*,

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 31, 2023, 4:47am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/6 "2023-05-31T04:47:01Z")

</div>

@Neelam_Zanvar

I think @Anton_H was asking if you have any documents in elastic with `3dxp_tag: 3dxp_service`

And my point is

> [@stephenb](#):
>
> `- 'path1*'`

That is not a valid path (does not appear to be valid)

If so you would see documents in elasticsearch with that log.path

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [May 31, 2023, 5:01am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/7 "2023-05-31T05:01:48Z")

</div>

oh, okay. Sorry. Yes there are documents with the d tag

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/e/5/e58ec0602dacbc1fb4c7117177892980287ab9f1.png)  
and I have given a valid path in the filebeat.yml I have just renamed it as path\* in the forum  
The path is  
'D:\Dss\R2022x\*\win\_b64\code\tomee\logs\localhost\_access\_log\*'

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 31, 2023, 5:24am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/8 "2023-05-31T05:24:51Z")

</div>

Can you show the entire JSON for that document? We want to see if there is a grok error tag.

Please paste it in as text not a screenshot!

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [May 31, 2023, 5:27am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/9 "2023-05-31T05:27:07Z")

</div>

```auto
{
  "_index": "3dxp_servicetrace-2023.05.30",
  "_id": "TchGbYgBCHIATQ4HfQFn",
  "_version": 1,
  "_score": 0,
  "_source": {
    "input": {
      "type": "log"
    },
    "message": "[30/May/2023:15:28:16.620 +0000] | 200 | 2 ms | 14 B | 172.31.40.179 | 172.31.40.179 | - | - | \"GET /3dcomment/monitoring/healthcheck HTTP/1.1\" | -",
    "host": {
      "ip": [
        "fe80::c02d:1110:7191:bb86",
        "172.31.40.179"
      ],
      "name": "EC2AMAZ-JC0BLVK",
      "mac": [
        "02-F0-50-1A-21-52"
      ],
      "os": {
        "type": "windows",
        "kernel": "10.0.17763.3406 (WinBuild.160101.0800)",
        "name": "Windows Server 2019 Datacenter",
        "family": "windows",
        "platform": "windows",
        "version": "10.0",
        "build": "17763.3406"
      },
      "id": "95a82d2c-5ad4-4b34-939b-2ede4078926e",
      "hostname": "EC2AMAZ-JC0BLVK",
      "architecture": "x86_64"
    },
    "log": {
      "file": {
        "path": "D:\\DassaultSystemes\\R2022x\\3DComment\\win_b64\\code\\tomee\\logs\\localhost_access_log..2023-05-30.txt"
      },
      "offset": 44993
    },
    "bytes": "14 B",
    "token": "-",
    "ecs": {
      "version": "8.0.0"
    },
    "duration": "2 ms",
    "remoteip": "172.31.40.179",
    "url": "/3dcomment/monitoring/healthcheck",
    "@version": "1",
    "@timestamp": "2023-05-30T15:28:35.067Z",
    "agent": {
      "ephemeral_id": "5bb38ab9-5228-4a1d-8c2a-05e8af51eb91",
      "type": "filebeat",
      "id": "2b3bda68-ddfc-41d7-98fe-b7004a2d064a",
      "name": "EC2AMAZ-JC0BLVK",
      "version": "8.7.0"
    },
    "cloud": {
      "image": {
        "id": "ami-0629500f751ea2bb5"
      },
      "service": {
        "name": "EC2"
      },
      "region": "ap-south-1",
      "availability_zone": "ap-south-1a",
      "account": {
        "id": "841773524416"
      },
      "provider": "aws",
      "instance": {
        "id": "i-0bf7a20925c81c13a"
      },
      "machine": {
        "type": "t2.2xlarge"
      }
    },
    "tags": [
      "beats_input_codec_plain_applied"
    ],
    "tag1": "-",
    "http_version": "1.1",
    "3dxp_tag": "3dxp_service",
    "type": "3dxp_servicetrace",
    "clientip": " 172.31.40.179",
    "method": "GET",
    "event": {
      "original": "[30/May/2023:15:28:16.620 +0000] | 200 | 2 ms | 14 B | 172.31.40.179 | 172.31.40.179 | - | - | \"GET /3dcomment/monitoring/healthcheck HTTP/1.1\" | -"
    },
    "date": "30/May/2023:15:28:16.620 +0000",
    "response": "200"
  },
  "fields": {
    "date": [
      "30/May/2023:15:28:16.620 +0000"
    ],
    "agent.version.keyword": [
      "8.7.0"
    ],
    "host.architecture.keyword": [
      "x86_64"
    ],
    "remoteip": [
      "172.31.40.179"
    ],
    "cloud.instance.id.keyword": [
      "i-0bf7a20925c81c13a"
    ],
    "host.name.keyword": [
      "EC2AMAZ-JC0BLVK"
    ],
    "bytes.keyword": [
      "14 B"
    ],
    "host.os.build.keyword": [
      "17763.3406"
    ],
    "host.hostname": [
      "EC2AMAZ-JC0BLVK"
    ],
    "type": [
      "3dxp_servicetrace"
    ],
    "host.mac": [
      "02-F0-50-1A-21-52"
    ],
    "cloud.availability_zone": [
      "ap-south-1a"
    ],
    "remoteip.keyword": [
      "172.31.40.179"
    ],
    "response.keyword": [
      "200"
    ],
    "host.ip.keyword": [
      "fe80::c02d:1110:7191:bb86",
      "172.31.40.179"
    ],
    "ecs.version.keyword": [
      "8.0.0"
    ],
    "host.os.version": [
      "10.0"
    ],
    "type.keyword": [
      "3dxp_servicetrace"
    ],
    "clientip": [
      " 172.31.40.179"
    ],
    "date.keyword": [
      "30/May/2023:15:28:16.620 +0000"
    ],
    "host.os.name": [
      "Windows Server 2019 Datacenter"
    ],
    "cloud.account.id.keyword": [
      "841773524416"
    ],
    "host.id.keyword": [
      "95a82d2c-5ad4-4b34-939b-2ede4078926e"
    ],
    "agent.name": [
      "EC2AMAZ-JC0BLVK"
    ],
    "host.name": [
      "EC2AMAZ-JC0BLVK"
    ],
    "host.os.version.keyword": [
      "10.0"
    ],
    "event.original": [
      "[30/May/2023:15:28:16.620 +0000] | 200 | 2 ms | 14 B | 172.31.40.179 | 172.31.40.179 | - | - | \"GET /3dcomment/monitoring/healthcheck HTTP/1.1\" | -"
    ],
    "method": [
      "GET"
    ],
    "cloud.region": [
      "ap-south-1"
    ],
    "host.os.type": [
      "windows"
    ],
    "agent.id.keyword": [
      "2b3bda68-ddfc-41d7-98fe-b7004a2d064a"
    ],
    "http_version": [
      "1.1"
    ],
    "input.type": [
      "log"
    ],
    "@version.keyword": [
      "1"
    ],
    "cloud.service.name.keyword": [
      "EC2"
    ],
    "log.offset": [
      44993
    ],
    "duration.keyword": [
      "2 ms"
    ],
    "tags": [
      "beats_input_codec_plain_applied"
    ],
    "host.architecture": [
      "x86_64"
    ],
    "cloud.provider": [
      "aws"
    ],
    "cloud.machine.type": [
      "t2.2xlarge"
    ],
    "agent.id": [
      "2b3bda68-ddfc-41d7-98fe-b7004a2d064a"
    ],
    "cloud.service.name": [
      "EC2"
    ],
    "ecs.version": [
      "8.0.0"
    ],
    "message.keyword": [
      "[30/May/2023:15:28:16.620 +0000] | 200 | 2 ms | 14 B | 172.31.40.179 | 172.31.40.179 | - | - | \"GET /3dcomment/monitoring/healthcheck HTTP/1.1\" | -"
    ],
    "host.hostname.keyword": [
      "EC2AMAZ-JC0BLVK"
    ],
    "clientip.keyword": [
      " 172.31.40.179"
    ],
    "agent.version": [
      "8.7.0"
    ],
    "host.os.family": [
      "windows"
    ],
    "token.keyword": [
      "-"
    ],
    "cloud.machine.type.keyword": [
      "t2.2xlarge"
    ],
    "3dxp_tag": [
      "3dxp_service"
    ],
    "input.type.keyword": [
      "log"
    ],
    "tags.keyword": [
      "beats_input_codec_plain_applied"
    ],
    "duration": [
      "2 ms"
    ],
    "host.os.build": [
      "17763.3406"
    ],
    "cloud.instance.id": [
      "i-0bf7a20925c81c13a"
    ],
    "host.ip": [
      "fe80::c02d:1110:7191:bb86",
      "172.31.40.179"
    ],
    "agent.type": [
      "filebeat"
    ],
    "host.os.kernel.keyword": [
      "10.0.17763.3406 (WinBuild.160101.0800)"
    ],
    "host.os.kernel": [
      "10.0.17763.3406 (WinBuild.160101.0800)"
    ],
    "@version": [
      "1"
    ],
    "host.os.name.keyword": [
      "Windows Server 2019 Datacenter"
    ],
    "method.keyword": [
      "GET"
    ],
    "host.id": [
      "95a82d2c-5ad4-4b34-939b-2ede4078926e"
    ],
    "http_version.keyword": [
      "1.1"
    ],
    "log.file.path.keyword": [
      "D:\\DassaultSystemes\\R2022x\\3DComment\\win_b64\\code\\tomee\\logs\\localhost_access_log..2023-05-30.txt"
    ],
    "agent.type.keyword": [
      "filebeat"
    ],
    "agent.ephemeral_id.keyword": [
      "5bb38ab9-5228-4a1d-8c2a-05e8af51eb91"
    ],
    "tag1": [
      "-"
    ],
    "cloud.region.keyword": [
      "ap-south-1"
    ],
    "cloud.image.id.keyword": [
      "ami-0629500f751ea2bb5"
    ],
    "host.mac.keyword": [
      "02-F0-50-1A-21-52"
    ],
    "tag1.keyword": [
      "-"
    ],
    "agent.name.keyword": [
      "EC2AMAZ-JC0BLVK"
    ],
    "message": [
      "[30/May/2023:15:28:16.620 +0000] | 200 | 2 ms | 14 B | 172.31.40.179 | 172.31.40.179 | - | - | \"GET /3dcomment/monitoring/healthcheck HTTP/1.1\" | -"
    ],
    "url": [
      "/3dcomment/monitoring/healthcheck"
    ],
    "url.keyword": [
      "/3dcomment/monitoring/healthcheck"
    ],
    "cloud.availability_zone.keyword": [
      "ap-south-1a"
    ],
    "token": [
      "-"
    ],
    "cloud.image.id": [
      "ami-0629500f751ea2bb5"
    ],
    "host.os.family.keyword": [
      "windows"
    ],
    "@timestamp": [
      "2023-05-30T15:28:35.067Z"
    ],
    "host.os.type.keyword": [
      "windows"
    ],
    "host.os.platform": [
      "windows"
    ],
    "cloud.account.id": [
      "841773524416"
    ],
    "host.os.platform.keyword": [
      "windows"
    ],
    "response": [
      "200"
    ],
    "bytes": [
      "14 B"
    ],
    "log.file.path": [
      "D:\\DassaultSystemes\\R2022x\\3DComment\\win_b64\\code\\tomee\\logs\\localhost_access_log..2023-05-30.txt"
    ],
    "cloud.provider.keyword": [
      "aws"
    ],
    "event.original.keyword": [
      "[30/May/2023:15:28:16.620 +0000] | 200 | 2 ms | 14 B | 172.31.40.179 | 172.31.40.179 | - | - | \"GET /3dcomment/monitoring/healthcheck HTTP/1.1\" | -"
    ],
    "agent.ephemeral_id": [
      "5bb38ab9-5228-4a1d-8c2a-05e8af51eb91"
    ],
    "3dxp_tag.keyword": [
      "3dxp_service"
    ]
  }
}

```

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [May 31, 2023, 5:29am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/10 "2023-05-31T05:29:01Z")

</div>

> [@Neelam\_Zanvar](#):
>
> ce of only one field in

is the syntax of if condition correct?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 31, 2023, 5:29am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/11 "2023-05-31T05:29:29Z")

</div>

> [@Neelam\_Zanvar](#):
>
> is the syntax of if condition correct?

Yeah We are looking at that... First look it looks correct...

Can you provide the JSON for the other type that is parsed and show us that please

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 31, 2023, 5:33am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/12 "2023-05-31T05:33:16Z")

</div>

@Neelam_Zanvar WAIT It IS Getting Parsed look the JSON closely

THIS is parsed maybe not correctly but it IS PARSED!

> [@Neelam\_Zanvar](#):
>
> ```auto
> "bytes": "14 B",
> "token": "-",
> "ecs": {
> "version": "8.0.0"
> },
> "duration": "2 ms",
> "remoteip": "172.31.40.179",
> "url": "/3dcomment/monitoring/healthcheck",
> .....
> "tag1": "-",
> "http_version": "1.1",
> "3dxp_tag": "3dxp_service",
> "type": "3dxp_servicetrace",
> "clientip": " 172.31.40.179",
> "method": "GET",
> "event": {
> "original": "[30/May/2023:15:28:16.620 +0000] | 200 | 2 ms | 14 B | 172.31.40.179 | 172.31.40.179 | - | - | \"GET /3dcomment/monitoring/healthcheck HTTP/1.1\" | -"
> },
> "date": "30/May/2023:15:28:16.620 +0000",
> "response": "200"
> },
> 
> ```

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [May 31, 2023, 6:05am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/13 "2023-05-31T06:05:10Z")

</div>

yes it is getting parsed, Thank you For the quick response. It is working as expected. Thank you for your time. I have another query , All the fields getting parsed by the grok are created in text format. For example HTTPDATE:timestamp is getting saved as text, How can i save it in date format using logstash pipeline only?

---

<div class="post-metadata">

**Author:** ![Anton\_H](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anton_h/32/10200_2.png) [@Anton\_H](https://discuss.elastic.co/u/Anton_H)\
**Post date:** [May 31, 2023, 7:59am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/14 "2023-05-31T07:59:48Z")

</div>

@Neelam_Zanvar I think this is the same issue we are discussing in your [Kibana visualisation-](https://discuss.elastic.co/t/kibana-visualisation/333176) question.  
I will try to answer your questions but am lacking time at the moment. Could you please answer the question in regards to the version of Elastic you are using?

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [May 31, 2023, 8:36am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/15 "2023-05-31T08:36:53Z")

</div>

its 8.7

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 31, 2023, 10:20am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/16 "2023-05-31T10:20:56Z")

</div>

For example HTTPDATE:timestamp is getting saved as text, How can i save it in date format using logstash pipeline only?

Use [the date plugin](https://www.elastic.co/guide/en/logstash/current/plugins-filters-date.html#plugins-filters-date-match) for conversion:

```auto
  date {
      match => ["date", "dd/MMM/yyyy:HH:mm:ss.SSS Z"]
      # timezone => "Asia/Dubai"
      target=> "@timestamp"
 }

```

Also you data pattern/view should be recreated in Kibana.

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [May 31, 2023, 10:36am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/17 "2023-05-31T10:36:36Z")

</div>

can u please show me how can i use it in my existing grok?

```auto
 grok {
        match => { "message" => ["\[%{ **HTTPDATE:date:date** }\] \| %{NUMBER:response} \| (?<duration>%{NUMBER} %{WORD}) \| (?<bytes>%{NUMBER} %{WORD}|%{DATA}) \| %{IP:remoteip} \| (%{DATA:clientip}|%{IP:clientip}) \| (%{WORD:token}|%{DATA:token}) \| (?<tag1>%{NUMBER} %{WORD}|%{DATA}) \| \"(?<method>%{WORD}) (?<url>%{URIPATHPARAM}) (?:HTTP/%{NUMBER:http_version})\" \| (%{EMAILADDRESS:email}|%{WORD:email}|%{DATA:email})"] }
    }

```

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 31, 2023, 10:41am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/18 "2023-05-31T10:41:55Z")

</div>

You cannot directly in grok:  
The documentation: _For example `%{NUMBER:num:int}` which converts the `num` semantic from a string to an integer. Currently the only supported conversions are **`int` and `float`**._

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [June 1, 2023, 6:07am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/19 "2023-06-01T06:07:46Z")

</div>

okay. thank you

---

<div class="post-metadata">

**Author:** ![Neelam\_Zanvar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/neelam_zanvar/32/103116_2.png) [@Neelam\_Zanvar](https://discuss.elastic.co/u/Neelam_Zanvar)\
**Post date:** [June 7, 2023, 5:59am UTC](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395/21 "2023-06-07T05:59:28Z")

</div>

How can it be done then?

[Next page](https://discuss.elastic.co/t/apply-grok-pattern-based-on-the-log-file-path/334395.md?page=2)
