# Extracting particular folder from the path and adding that to a field

**URL:** <https://discuss.elastic.co/t/extracting-particular-folder-from-the-path-and-adding-that-to-a-field/142277>\
**Category:** Logstash\
**Created:** [July 31, 2018, 5:47am UTC](https://discuss.elastic.co/t/extracting-particular-folder-from-the-path-and-adding-that-to-a-field/142277 "2018-07-31T05:47:38Z")\
**Posts on this page:** 1\
**Showing post:** 4

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 1, 2018, 1:11pm UTC](https://discuss.elastic.co/t/extracting-particular-folder-from-the-path-and-adding-that-to-a-field/142277/4 "2018-08-01T13:11:18Z")

</div>

OK, so a UNIX path contain directory names separated by /. A directory name cannot contain /. So you could either go after the 4th directory name, or the last but one directory name. Either of these should work

```
    grok { match => ["message", "^/[^/]+/[^/]+/[^/]+/(?<dir1>[^/]+)" ] }
    grok { match => ["message", "/(?<dir2>[^/]+)/[^/]+/[^/]+$" ] }
```

---

_[View the full topic](https://discuss.elastic.co/t/extracting-particular-folder-from-the-path-and-adding-that-to-a-field/142277)._
