# Extract value from path in logstash

**URL:** <https://discuss.elastic.co/t/extract-value-from-path-in-logstash/337936>\
**Category:** Elasticsearch\
**Tags:** elastic-stack-monitoring\
**Created:** [July 8, 2023, 12:20pm UTC](https://discuss.elastic.co/t/extract-value-from-path-in-logstash/337936 "2023-07-08T12:20:18Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Indeed2000](https://avatars.discourse-cdn.com/v4/letter/i/dc4da7/32.png) [@Indeed2000](https://discuss.elastic.co/u/Indeed2000)\
**Post date:** [July 8, 2023, 12:20pm UTC](https://discuss.elastic.co/t/extract-value-from-path-in-logstash/337936/1 "2023-07-08T12:20:18Z")

</div>

Hi need to extract value from path in logstash,  
here is my logpath:  
`/data/app/20230707/*/*`

```auto
/data/app1/20230707/host1/*.log
/data/app2/20230707/host2/*.log

```

need to extract these field from path (FYI: hostname must be overwrite host)  
data=constant  
app=variable means app name  
date of log=20230707  
hostname=host1 or host2

here is my logstash config:

```auto
input {
  file {
    path => "/data/app/20230707/*/*"
    start_position => "beginning"
    sincedb_path => "/dev/null"
  }
}

filter {
  if [message] =~ /\[SqlExceptionHelper\] SQL (Error|Warning Code):/ {
    grok {
      match => {
        "message" => [
          "%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:loglevel} %{DATA:thread} \[SqlExceptionHelper\] SQL Error: -%{INT:db_errorcode1}, SQLState: %{WORD:sql_state1}",
          "%{TIMESTAMP_ISO8601:timestamp} %{LOGLEVEL:loglevel} %{DATA:thread} \[SqlExceptionHelper\] SQL Warning Code: %{INT:db_errorcode2}, SQLState: %{WORD:sql_state2}"
        ]
      }
    }

    date {
      match => ["timestamp", "YYYY-MM-dd HH:mm:ss,SSS"]
    }
  } else if [message] =~ /(AMQ|ARJUNA|COM|EJBCLIENT|ELY|HCANN|HHH|HSEARCH|HV|IJ|ISNPHIB|ISPN|JBERET|JBREM|JBTHR|JBWEB|JBWS|JIPI|JNDIWFHTTP|MODCLUSTER|MSC|PBOX|PROBE|RESTEASY|TXNWFHTTP|UT|UTJS|VFS|WELD|WFCMTOOL|WFHTTP|WFHTTPEJB|WFLY|WFMIGRCLI|WFNAM|WFSM|WFTXN|XNIO|jlibaio)/ {
    grok {
      match => { "message" => ".*\b(?<jboss_errors>(?:AMQ\w*|ARJUNA\w*|COM\w*|EJBCLIENT\w*|ELY\w*|HCANN\w*|HHH\w*|HSEARCH\w*|HV\w*|IJ\w*|ISNPHIB\w*|ISPN\w*|JBERET\w*|JBREM\w*|JBTHR\w*|JBWEB\w*|JBWS\w*|JIPI\w*|JNDIWFHTTP\w*|MODCLUSTER\w*|MSC\w*|PBOX\w*|PROBE\w*|RESTEASY\w*|TXNWFHTTP\w*|UT\w*|UTJS\w*|VFS\w*|WELD\w*|WFCMTOOL\w*|WFHTTP\w*|WFHTTPEJB\w*|WFLY\w*|WFMIGRCLI\w*|WFNAM\w*|WFSM\w*|WFTXN\w*|XNIO\w*|jlibaio\w*)\b).*" }
    }
    grok {
      match => { "message" => "%{TIMESTAMP_ISO8601:timestamp}\s+%{LOGLEVEL:loglevel}\s+%{DATA:id}\s+\[%{DATA:class}\]" }
    }
    if "_grokparsefailure" in [tags] {
      drop { }
    }
    mutate {
      remove_field => ["message", "@version", "event"] # Optionally remove unnecessary fields
    }
    date {
      match => ["timestamp", "YYYY-MM-dd HH:mm:ss,SSS"]
    }
  }
  else {
    drop {}
  }
}

```

Any idea?  
Thanks,

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2023, 12:20pm UTC](https://discuss.elastic.co/t/extract-value-from-path-in-logstash/337936/2 "2023-08-05T12:20:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
