# Extract folder name as field in logstash

**URL:** <https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 18, 2022, 7:05am UTC](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026 "2022-05-18T07:05:58Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [May 18, 2022, 7:05am UTC](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026/1 "2022-05-18T07:05:59Z")

</div>

Hi everyone  
The following is my filebeat input in my yml file-

```auto
filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.

# filestream is an input for collecting log messages from files.
- type: log

  # Change to true to enable this input configuration.
  enabled: true

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - C:\elk stack\logs\*\*\*\access.log

  tags: ["access"]

```

How can i extract a folder name as a field in my logstash config file?  
for example, if my filepath is

```auto
C:\elk stack\logs\unit 1\LOGS-2022-1-2-12-30-17\lighttpd-2022-1-2-12-30-17\access.log

```

I need "unit 1" as an extracted value in a field named "tail\_no."

Help would be appreciated

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 18, 2022, 7:46am UTC](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026/2 "2022-05-18T07:46:54Z")

</div>

From some reason split by \ is working in Ruby as split("\") -double backslash,however LS from some reason cannot accept that. If you replace with a special character like | or # then split it's working fine.

```auto
    mutate {
         copy => { "message" => "filepath" }
      }
	 mutate {
	    gsub => ["filepath", "[^\\]+$", "" ]
	 }
	 mutate {
	   gsub => ["filepath", "[\\]", "|" ]
	 }
	 mutate {
	   split => { "filepath" => '|' }
	   add_field => { "tail_no" => '%{[filepath][3]}' }
	 }

```

---

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [May 18, 2022, 9:24am UTC](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026/3 "2022-05-18T09:24:05Z")

</div>

my file path gets saved in the field called log.file.path  
how do i change your code accordingly cause right now i am getting this as the tail\_no. field -  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/5/35b89150a5c8df9d984cdbca16fb294ea6d2242f.png)

---

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [May 18, 2022, 9:57am UTC](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026/4 "2022-05-18T09:57:51Z")

</div>

i also tried replacing "filepath" with "[log][file][path]" but it still gives the tail\_no. as %{[log][file][path][3]}

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 18, 2022, 11:26am UTC](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026/5 "2022-05-18T11:26:26Z")

</div>

This will work:

```auto
  mutate {
         copy => { "[log][file][path]" => "filepath" }
      }
	 mutate {
	    gsub => ["filepath", "[^\\]+$", "" ]
	 }
	 mutate {
	   gsub => ["filepath", "[\\]", "|" ]
	 }
	 mutate {
	   split => { "filepath" => '|' }
	   add_field => { "tail_no" => '%{[filepath][3]}' }
	 }

```

---

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [May 18, 2022, 12:43pm UTC](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026/6 "2022-05-18T12:43:42Z")

</div>

it works, thank you so much!

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [May 19, 2022, 4:27am UTC](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026/7 "2022-05-19T04:27:58Z")

</div>

Also you can have a cleaner output with @metadata

```auto
   mutate {
        copy => { "[log][file][path]" => "[@metadata][filepath]" }
     }
	 mutate {
	    gsub => ["[@metadata][filepath]", "[^\\]+$", "" ]
	 }
	 mutate {
	   gsub => ["[@metadata][filepath]", "[\\]", "|" ]
	 }
	 mutate {
	   split => { "[@metadata][filepath]" => '|' }
	   add_field => { "tail_no" => '%{[@metadata][filepath][3]}' }
	 }

```

---

<div class="post-metadata">

**Author:** ![anushka1203](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anushka1203/32/98018_2.png) [@anushka1203](https://discuss.elastic.co/u/anushka1203)\
**Post date:** [May 19, 2022, 4:38am UTC](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026/8 "2022-05-19T04:38:06Z")

</div>

noted. will implement this. thanks again!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 16, 2022, 6:38am UTC](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026/9 "2022-06-16T06:38:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
