# File input Path variable

**URL:** <https://discuss.elastic.co/t/file-input-path-variable/102907>\
**Category:** Logstash\
**Created:** [October 5, 2017, 8:10pm UTC](https://discuss.elastic.co/t/file-input-path-variable/102907 "2017-10-05T20:10:37Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [October 5, 2017, 8:10pm UTC](https://discuss.elastic.co/t/file-input-path-variable/102907/1 "2017-10-05T20:10:37Z")

</div>

My logstash.conf file is using the file input as such:

```
file{
	path => "${PWD}/data/**/log.file"
	start_position => beginning
	ignore_older => 0
	sincedb_path => "${PWD}/software_files/logstash-5.6.1/logstash_use/null"
	type => "csv"
}

```

Where PWD is the working directory where the Windows script is being ran from. The directory where my file is located is:

> D:\ELK\osi\_ELK-5.6.1/data/cust/role/host/log/log.file

Now Logstash reads the file in as such:

> D:\\ELK\\osi\_ELK-5.6.1/data/cust/role/host/log/log.file

My question is why does Logstash add an extra \ within the variable PWD? I am using a grok to parse information from the path variable and the double \ causes the logs to get tagged with \_grokparsefailure.

Thanks!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 5, 2017, 8:22pm UTC](https://discuss.elastic.co/t/file-input-path-variable/102907/2 "2017-10-05T20:22:24Z")

</div>

Exactly where are you seeing the double backslashes? Use copy/paste.

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [October 5, 2017, 8:28pm UTC](https://discuss.elastic.co/t/file-input-path-variable/102907/3 "2017-10-05T20:28:47Z")

</div>

In the fails.txt where I put logs that get tagged with \_grokparsefailure this is a log line.

`"tags":["_grokparsefailure"],"path":"D:\\ELK\\osi_ELK-5.6.1/data/cust/role/host/log/log.file","datestamp":"17/09/22 12:00:41.295"`

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 5, 2017, 9:14pm UTC](https://discuss.elastic.co/t/file-input-path-variable/102907/4 "2017-10-05T21:14:04Z")

</div>

The `path` field doesn't contain double backslashes, it's just how JSON serialization works. Your grok expression fails for some other reason.

> **[Escape character](https://en.wikipedia.org/wiki/Escape_character)**
>
> In computing and telecommunication, an escape character is a character which invokes an alternative interpretation on subsequent characters in a character sequence. An escape character is a particular case of metacharacters. Generally, the judgment of whether something is an escape character or not depends on context. Escape characters are part of the syntax for many programming languages, data formats, and communication protocols. For a given alphabet an escape character's purpose is to start ...

---

<div class="post-metadata">

**Author:** ![CDR](https://avatars.discourse-cdn.com/v4/letter/c/d9b06d/32.png) [@CDR](https://discuss.elastic.co/u/CDR)\
**Post date:** [October 5, 2017, 9:21pm UTC](https://discuss.elastic.co/t/file-input-path-variable/102907/5 "2017-10-05T21:21:06Z")

</div>

But when I create create a grok that only utilizes a single "\" it fails. But when I use one that is "\\" in those instances above it does not get tagged as grok parse failure.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 6, 2017, 5:34am UTC](https://discuss.elastic.co/t/file-input-path-variable/102907/6 "2017-10-06T05:34:33Z")

</div>

Backslashes have a special meaning in regular expressions so they need to be escaped there as well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2017, 5:34am UTC](https://discuss.elastic.co/t/file-input-path-variable/102907/7 "2017-11-03T05:34:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
