# Help with file name to date logstash grok

**URL:** <https://discuss.elastic.co/t/help-with-file-name-to-date-logstash-grok/341592>\
**Category:** Logstash\
**Created:** [August 24, 2023, 4:43pm UTC](https://discuss.elastic.co/t/help-with-file-name-to-date-logstash-grok/341592 "2023-08-24T16:43:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ethranes](https://avatars.discourse-cdn.com/v4/letter/e/e56c9b/32.png) [@ethranes](https://discuss.elastic.co/u/ethranes)\
**Post date:** [August 24, 2023, 4:43pm UTC](https://discuss.elastic.co/t/help-with-file-name-to-date-logstash-grok/341592/1 "2023-08-24T16:43:43Z")

</div>

Hi, the date isn't included in my log files. But the filename itself has the date. So I'm trying to extract the year month and day from the filename and then put that into a field. But logstash can't parse my filename, I'm not sure what the issue is, here is my logstash config. Any help is appreciated!

I've used the grok debugger in kibana, and it's able to parse my filenames correctly so it's not an issue with the grok expression itself

```auto
input {
  file {
    path => "C:/Users/nwilc/AppData/Roaming/MetaQuotes/Terminal/73B7A2420D6397DFF9014A20F1201F97/Logs/UTF8/20230505.log"
    exclude => ["*metaeditor.log"]
    start_position => "beginning"
    sincedb_path => "NUL"
  }
}

filter {
  grok {
    match => { "log.file.path" => "./(?<file_year>[0-9]{4})(?<file_month>[0-9]{2})(?<file_day>[0-9]{2})\.log$" }
    tag_on_failure => ["grok_fail_filename"]
  }
  grok {
    match => {
      "message" => "^%{WORD:code}\t%{INT:number}\t%{TIME:timestamp}\t%{NOTSPACE:category}\t%{GREEDYDATA:log_message}"
    }
  }
  mutate {
    add_field => { "full_timestamp" => "%{file_year}-%{file_month}-%{file_day} %{timestamp}" }
  }
  date {
    match => ["full_timestamp", "YYYY-MM-dd HH:mm:ss.SSS"]
    target => "@timestamp"
    remove_field => ["full_timestamp", "file_year", "file_month", "file_day"]
  }
}

output {
  elasticsearch {
    hosts => ["http://localhost:9200"]
    index => "metatrader-5-logs"
  }
}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 24, 2023, 4:58pm UTC](https://discuss.elastic.co/t/help-with-file-name-to-date-logstash-grok/341592/2 "2023-08-24T16:58:44Z")

</div>

> [@ethranes](#):
>
> `match => { "log.file.path" =`

Can you try [log][file][path] instead of log.file.path?

---

<div class="post-metadata">

**Author:** ![ethranes](https://avatars.discourse-cdn.com/v4/letter/e/e56c9b/32.png) [@ethranes](https://discuss.elastic.co/u/ethranes)\
**Post date:** [August 24, 2023, 5:07pm UTC](https://discuss.elastic.co/t/help-with-file-name-to-date-logstash-grok/341592/3 "2023-08-24T17:07:15Z")

</div>

ohh perfect thank you so much, that's sorted it!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2023, 5:07pm UTC](https://discuss.elastic.co/t/help-with-file-name-to-date-logstash-grok/341592/4 "2023-09-21T17:07:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
