# Extract information from Prospectors Path

**URL:** <https://discuss.elastic.co/t/extract-information-from-prospectors-path/84192>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 2, 2017, 1:11am UTC](https://discuss.elastic.co/t/extract-information-from-prospectors-path/84192 "2017-05-02T01:11:23Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![rake](https://avatars.discourse-cdn.com/v4/letter/r/8e8cbc/32.png) [@rake](https://discuss.elastic.co/u/rake)\
**Post date:** [May 2, 2017, 1:11am UTC](https://discuss.elastic.co/t/extract-information-from-prospectors-path/84192/1 "2017-05-02T01:11:23Z")

</div>

Is it possible to extract information from Filebeat prospectors path?  
Here is an example:  
filebeat.prospectors:

- input\_type: log  
paths:
  - /log/_/test/_/_/_.log

I wanted to extract the values of \* from the paths and appends them as filebeat message meta informations.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [May 3, 2017, 11:27am UTC](https://discuss.elastic.co/t/extract-information-from-prospectors-path/84192/2 "2017-05-03T11:27:34Z")

</div>

This is currently not possible in filebeat, but you could extract such fields with logstash from the path field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2017, 11:32am UTC](https://discuss.elastic.co/t/extract-information-from-prospectors-path/84192/3 "2017-05-31T11:32:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
