# Dynamic input file name

**URL:** <https://discuss.elastic.co/t/dynamic-input-file-name/25951>\
**Category:** Logstash\
**Created:** [July 20, 2015, 9:21pm UTC](https://discuss.elastic.co/t/dynamic-input-file-name/25951 "2015-07-20T21:21:53Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raman\_Saini](https://avatars.discourse-cdn.com/v4/letter/r/7bcc69/32.png) [@Raman\_Saini](https://discuss.elastic.co/u/Raman_Saini)\
**Post date:** [July 20, 2015, 9:21pm UTC](https://discuss.elastic.co/t/dynamic-input-file-name/25951/1 "2015-07-20T21:21:53Z")

</div>

Hi,

I have log file whose name changes as per date. How to set path in the input filter. i have given below path:

"/www/redhat/ews-abc-uat/tomcat7/logs/access.`date '+%F'`.log"

Its not working. Please suggest.

Regards,  
Raman

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 20, 2015, 9:33pm UTC](https://discuss.elastic.co/t/dynamic-input-file-name/25951/2 "2015-07-20T21:33:16Z")

</div>

That kind of filename pattern isn't supported. Why not just use /www/redhat/ews-abc-uat/tomcat7/logs/access.\*.log?

---

<div class="post-metadata">

**Author:** ![Raman\_Saini](https://avatars.discourse-cdn.com/v4/letter/r/7bcc69/32.png) [@Raman\_Saini](https://discuss.elastic.co/u/Raman_Saini)\
**Post date:** [July 20, 2015, 9:38pm UTC](https://discuss.elastic.co/t/dynamic-input-file-name/25951/3 "2015-07-20T21:38:47Z")

</div>

Thanks for the reply. There are many files under logs directory and i want to process only current file not all. Is there any other option so that it will pick up only current date file ?

Regards,  
Raman

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 20, 2015, 9:48pm UTC](https://discuss.elastic.co/t/dynamic-input-file-name/25951/4 "2015-07-20T21:48:23Z")

</div>

> There are many files under logs directory and i want to process only current file not all.

Are you having actual issues with the number of files that Logstash needs to keep open?

> Is there any other option so that it will pick up only current date file ?

Short of periodically generating a Logstash configuration file with the currently correct filename pattern, I don't believe there is a way.

---

<div class="post-metadata">

**Author:** ![jigarpatel13533](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jigarpatel13533/32/18675_2.png) [@jigarpatel13533](https://discuss.elastic.co/u/jigarpatel13533)\
**Post date:** [June 8, 2017, 6:34am UTC](https://discuss.elastic.co/t/dynamic-input-file-name/25951/5 "2017-06-08T06:34:46Z")

</div>

> [@magnusbaeck](#):
>
> Short of periodically generating a Logstash configuration file with the currently correct filename pattern, I don't believe there is a way.

Hi Magnus,

I am facing the same issue in logstash 2.1.

Can we get sysdate inside input {} in configuration file.  
If we can have sysdate, then we should create dynamic path using sysdate inside input {}. I think this is the only way.

Please let us know if it is possible.

---

<div class="post-metadata">

**Author:** ![pts0](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pts0/32/17811_2.png) [@pts0](https://discuss.elastic.co/u/pts0)\
**Post date:** [June 8, 2017, 6:41am UTC](https://discuss.elastic.co/t/dynamic-input-file-name/25951/6 "2017-06-08T06:41:40Z")

</div>

For me it look like a great use case for config file reload (new since 2.3):  
[https://www.elastic.co/guide/en/logstash/current/reloading-config.html](https://www.elastic.co/guide/en/logstash/current/reloading-config.html)

Just rewrite config file with the current filename after rotating logs.

---

<div class="post-metadata">

**Author:** ![jigarpatel13533](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jigarpatel13533/32/18675_2.png) [@jigarpatel13533](https://discuss.elastic.co/u/jigarpatel13533)\
**Post date:** [June 9, 2017, 4:02am UTC](https://discuss.elastic.co/t/dynamic-input-file-name/25951/7 "2017-06-09T04:02:24Z")

</div>

Hi,

Thanks for the suggestion. I really appreciate the effort.  
It's nice concept to reload the config without stopping logstash.

But let me tell you, in my case a bunch of new log files generated every 24 hours. It will not be possible to change the config file every 24 hours and hit config reload. You know it's not a kind of automated way. We need to feed something to logstash everyday.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 9, 2017, 5:17am UTC](https://discuss.elastic.co/t/dynamic-input-file-name/25951/8 "2017-06-09T05:17:06Z")

</div>

> But let me tell you, in my case a bunch of new log files generated every 24 hours. It will not be possible to change the config file every 24 hours and hit config reload. You know it's not a kind of automated way. We need to feed something to logstash everyday.

It's not clear why this can't be automated. It's also not clear why you need to specify an exact filename rather than using "\*.log" or some other filename pattern that matches all log files, past an future. Logstash will pick up newly created files with matching names within seconds.

---

<div class="post-metadata">

**Author:** ![jigarpatel13533](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jigarpatel13533/32/18675_2.png) [@jigarpatel13533](https://discuss.elastic.co/u/jigarpatel13533)\
**Post date:** [June 9, 2017, 5:30am UTC](https://discuss.elastic.co/t/dynamic-input-file-name/25951/9 "2017-06-09T05:30:24Z")

</div>

> [@magnusbaeck](#):
>
> It's not clear why this can't be automated. It's also not clear why you need to specify an exact filename rather than using "\*.log" or some other filename pattern that matches all log files, past an future. Logstash will pick up newly created files with matching names within seconds.

Please refer below post. You'll get entire problem. Need your assistance.

> [@Using wildcard character in logstash input](https://discuss.elastic.co/t/using-wildcard-character-in-logstash-input/88585):
>
> Hi, I am using logstash 2.1 in Windows Server 2008 R2 OS. (Version Corrected) I have some log files at some another server, and I am taking them as input for my logstash. Shared Path : \\MIB030065\share2\Statoil-logs\Sharepoint/ST-W2284-20170607-0841.log Now if I writing below in config file, it's discovering the changes (happening real time) in the same file. input{ file{ type =\> "logs" path =\> ["\\MIB030065\share2\Statoil-logs\Sharepoint/ST-W2284-20170607.log"]\* codec =\> multiline { …

Thanks in advance, Magnus !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 4:03am UTC](https://discuss.elastic.co/t/dynamic-input-file-name/25951/10 "2022-11-04T04:03:08Z")

</div>


