# Extract hostname from log file name

**URL:** <https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761>\
**Category:** Logstash\
**Created:** [October 25, 2023, 8:28pm UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761 "2023-10-25T20:28:33Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Indeed2000](https://avatars.discourse-cdn.com/v4/letter/i/dc4da7/32.png) [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Post date:** [October 25, 2023, 8:28pm UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761/1 "2023-10-25T20:28:34Z")

</div>

Hi  
on logstash need to use file as input, output as http.

now question is how can i extract hostname from log filename, here is file name:  
/tmp/log.hostname1.20230720  
/tmp/log.hostname2.20230720

Any idea  
Thanks

---

<div class="post-metadata">

**Author:** ![PodarcisMuralis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/podarcismuralis/32/122606_2.png) [@PodarcisMuralis](https://discuss.elastic.co/u/PodarcisMuralis)\
**Post date:** [October 25, 2023, 9:38pm UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761/2 "2023-10-25T21:38:49Z")

</div>

Hi. You can try this. It may be wrong but you can adjust it accordingly.

```auto
filter {
  grok {
    match => {
      "@source_path" => "%{TIMESTAMP_ISO8601}%{NOTSPACE}%{SPACE}%{GREEDYDATA}"
    }
    match => {
      "@source_path" => "/tmp/log\.hostname%{NOTSPACE:hostname}\.20230720"
    }
  }

  mutate {
    add_field => { "hostname" => "%{hostname}" }
  }
}

```

Extract hostname and create it as a field.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 26, 2023, 2:22am UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761/3 "2023-10-26T02:22:05Z")

</div>

> [@Indeed2000](#):
>
> /tmp/log.hostname2.20230720

If your files have always this name pattern and are always in the same path, it would be easier to use a dissect filter.

Logstash will save the file path in a field named `path` or `log.file.path` depending if you have ecs compatibility enabled or not.

So the filter would be something like this:

```auto
filter {
    dissect {
        mapping => {
            "fieldName" => "/tmp/log.%{[host][hostname]}.%{}"
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![ritchierich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ritchierich/32/4329_2.png) [@ritchierich](https://discuss.elastic.co/u/ritchierich)\
**Post date:** [October 26, 2023, 4:30am UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761/4 "2023-10-26T04:30:25Z")

</div>

@Indeed2000

Here are two more examples using grok and dissect each extracting hostname the `path` field as `path_hostname`. Also, extracting date as `path_date`.

**Dissect:**

```auto
filter { 

  dissect {
        mapping => {
            "path" => "/tmp/log.%{path_hostname}.%{path_date}"
        }
    }
}

```

**Grok:**

```auto
filter { 

  grok {
    match => {
      "path" => "/tmp/log.%{HOSTNAME:path_hostname}.%{WORD:path_date}"
    }

  }
}

```

Hopefully, any of these options help.

---

<div class="post-metadata">

**Author:** ![Indeed2000](https://avatars.discourse-cdn.com/v4/letter/i/dc4da7/32.png) [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Post date:** [October 26, 2023, 5:00pm UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761/5 "2023-10-26T17:00:55Z")

</div>

@leandrojmp @ritchierich @PodarcisMuralis  
Neither work for me, probably i miss something, here is more pattern examples:

/tmp/log.hostname1.20230720  
/tmp/log.hostname2.20230720  
/tmp/log.hostname5.20230720  
/tmp/log.hostname6.20230722  
/tmp/log.hostname7.20230723

Expected output field:  
hostname1 As host  
20230720 As date

Any idea?  
Thanks

---

<div class="post-metadata">

**Author:** ![ritchierich](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ritchierich/32/4329_2.png) [@ritchierich](https://discuss.elastic.co/u/ritchierich)\
**Post date:** [October 26, 2023, 5:13pm UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761/6 "2023-10-26T17:13:21Z")

</div>

Please share your logstash config and example of the logstash output

---

<div class="post-metadata">

**Author:** ![Indeed2000](https://avatars.discourse-cdn.com/v4/letter/i/dc4da7/32.png) [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Post date:** [October 26, 2023, 7:56pm UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761/7 "2023-10-26T19:56:05Z")

</div>

@ritchierich

```auto

input {
  
  file 
  {
    path => "/tmp/log.*.????????"
    start_position => "beginning"
    sincedb_path => "/dev/null"
    exclude => ["*.gz" , "*.bz2" , "*.slice"]
    codec => plain { charset => "UTF-8" }
  }
 
} 

filter { 

  dissect {
        mapping => {
            "path" => "/tmp/log.%{path_hostname}.%{path_date}"
        }
    }

}

output 
{

  http {
    url => "%{[URL]}"
    http_method => "post"
    format => message
    message => 'host=%{[path_hostname]},id=%{[id]} trace="%{[trace]}"'

    http_compression => true
    headers => [
      'Authorization', 'Token %{[TOKEN_INFLUX]}'
    ]
  }

  stdout { codec => rubydebug }

    }

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 26, 2023, 7:58pm UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761/8 "2023-10-26T19:58:57Z")

</div>

You need to share the output you are getting, without it is not possible to know what may be the error.

You have a stdout output, please share this output.

Another thing is this that I mentioned before

> Logstash will save the file path in a field named `path` or `log.file.path` depending if you have ecs compatibility enabled or not.

If you are using Logstash 8, ecs compatibility is enabled by default, so you will not have a `path` field, but you will have `[log][file][path]`, so you need to use this field.

---

<div class="post-metadata">

**Author:** ![Indeed2000](https://avatars.discourse-cdn.com/v4/letter/i/dc4da7/32.png) [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Post date:** [October 26, 2023, 8:23pm UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761/9 "2023-10-26T20:23:27Z")

</div>

@leandrojmp I’m using logstash 8.9.1

Try these

"path" =\> "/tmp/log.%{path\_hostname}.%{path\_date}"

"log.file.path" =\> "/tmp/log.%{path\_hostname}.%{path\_date}"

"[log][file][path]" =\> "/tmp/log.%{path\_hostname}.%{path\_date}"

Still not work.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 26, 2023, 8:44pm UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761/10 "2023-10-26T20:44:26Z")

</div>

As mentioned before, you need to share the output you are getting.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 23, 2023, 8:44pm UTC](https://discuss.elastic.co/t/extract-hostname-from-log-file-name/345761/11 "2023-11-23T20:44:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
