# Extract substring from the path

**URL:** <https://discuss.elastic.co/t/extract-substring-from-the-path/346787>\
**Category:** Logstash\
**Created:** [November 9, 2023, 12:09pm UTC](https://discuss.elastic.co/t/extract-substring-from-the-path/346787 "2023-11-09T12:09:07Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Xhar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/xhar/32/126590_2.png) [@Xhar](https://discuss.elastic.co/u/Xhar)\
**Post date:** [November 9, 2023, 12:09pm UTC](https://discuss.elastic.co/t/extract-substring-from-the-path/346787/1 "2023-11-09T12:09:07Z")

</div>

in this config

```auto
input {
  file {
    mode => "read"
    path => "/opt/stromReciever/parsed_data/changedRights/csv/*.json"
    start_position => "beginning"
    sincedb_path => "/dev/null"
    codec => "json"
    type => "csv"
  }

  file {
    mode => "read"
    path => "/opt/stromReciever/parsed_data/changedRights/cve_mitre/*.json"
    start_position => "beginning"
    sincedb_path => "/dev/null"
    codec => "json"
    type => "cve_mitre"
  }

  file {
    mode => "read"
    path => "/opt/stromReciever/parsed_data/changedRights/cwe_mitre/*.json"
    start_position => "beginning"
    sincedb_path => "/dev/null"
    codec => "json"
    type => "cwe_mitre"
  }

  file {
    mode => "read"
    path => "/opt/stromReciever/parsed_data/changedRights/ibm_x_force/*.json"
    start_position => "beginning"
    sincedb_path => "/dev/null"
    codec => "json"
    type => "ibm_x_force"
  }

```

and 10 more similar inputs.  
How can i extract name of any, that located between parsed\_data/changedRights/ and /\*.json  
I need it to make opensearch index based on subfolder name, but write only one input, smt like this:

```auto
input {
  file {
    mode => "read"
    path => "/opt/stromReciever/parsed_data/changedRights/*/*.json"
    start_position => "beginning"
    sincedb_path => "/dev/null"
    codec => "json"
  }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2023, 12:09pm UTC](https://discuss.elastic.co/t/extract-substring-from-the-path/346787/2 "2023-11-09T12:09:08Z")

</div>

OpenSearch/OpenDistro are AWS run products and differ from the original Elasticsearch and Kibana products that Elastic builds and maintains. You may need to contact them directly for further assistance.

(This is an automated response from your friendly Elastic bot. Please report this post if you have any suggestions or concerns :elasticheart: )

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [November 9, 2023, 12:43pm UTC](https://discuss.elastic.co/t/extract-substring-from-the-path/346787/3 "2023-11-09T12:43:16Z")

</div>

Which Logstash version are you using?

You can get this information using a parsing filter like `dissect` on the field that has the path of the file.

Something like this:

```auto
filter {
    dissect {
        mapping => {
            "[log][file][path]" => "/opt/stromReciever/parsed_data/changedRights/%{index_name}/*.json"
        }
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 7, 2023, 12:44pm UTC](https://discuss.elastic.co/t/extract-substring-from-the-path/346787/4 "2023-12-07T12:44:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
