# Grok Patterns taken from another file

**URL:** <https://discuss.elastic.co/t/grok-patterns-taken-from-another-file/156984>\
**Category:** Logstash\
**Created:** [November 16, 2018, 6:33am UTC](https://discuss.elastic.co/t/grok-patterns-taken-from-another-file/156984 "2018-11-16T06:33:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Priyaranjan\_Mudliar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priyaranjan_mudliar/32/33726_2.png) [@Priyaranjan\_Mudliar](https://discuss.elastic.co/u/Priyaranjan_Mudliar)\
**Post date:** [November 16, 2018, 6:33am UTC](https://discuss.elastic.co/t/grok-patterns-taken-from-another-file/156984/1 "2018-11-16T06:33:43Z")

</div>

Can i change my logstash configuration file dynamically ? Like i need to have different grok patterns for different file paths.  
Can i use something like "translate plugin" to change values of grok in the configuration file from another file(ex: YAML, JSON etc).

Please help. Thanks

---

<div class="post-metadata">

**Author:** ![Tek\_Chand](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tek_chand/32/34318_2.png) [@Tek\_Chand](https://discuss.elastic.co/u/Tek_Chand)\
**Post date:** [November 16, 2018, 6:43am UTC](https://discuss.elastic.co/t/grok-patterns-taken-from-another-file/156984/2 "2018-11-16T06:43:57Z")

</div>

@Priyaranjan_Mudliar, Yes, you can write different grok pattern for different file path. You can define the fields in `filebeat.yml` for every log path and then you can use that filed in logstash to use different grok pattern for each log path. Please refer the below example for `filebeat.yml` and logstash configuration:

For Filebeat.yml:

```auto
- type: log
  enabled: true
  paths:
     - /var/log/syslog
  fields_under_root: true
  fields:
    type: syslog_logs

- type: log
  enabled: true
  paths:
     - /var/log/auth.log
  fields_under_root: true
  fields:
    type: auth_logs

```

Logstash configuration:

```auto
if [type] == "syslog_logs" {
grok {

}

else [type] == "auth_logs" { 
grok {

      }

```

Hops so above config will help you.

Thanks.

---

<div class="post-metadata">

**Author:** ![Priyaranjan\_Mudliar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/priyaranjan_mudliar/32/33726_2.png) [@Priyaranjan\_Mudliar](https://discuss.elastic.co/u/Priyaranjan_Mudliar)\
**Post date:** [November 16, 2018, 6:55am UTC](https://discuss.elastic.co/t/grok-patterns-taken-from-another-file/156984/3 "2018-11-16T06:55:41Z")

</div>

Thanks for the reply... but i actually don't want this to be written on the configuration file itself instead i want the if and else part taken from another file. Is it possible ? Anyways i will work with the above method if its not possible.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2018, 6:55am UTC](https://discuss.elastic.co/t/grok-patterns-taken-from-another-file/156984/4 "2018-12-14T06:55:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
