# Help with Grok patterns to parse date and name index from path

**URL:** <https://discuss.elastic.co/t/help-with-grok-patterns-to-parse-date-and-name-index-from-path/141721>\
**Category:** Logstash\
**Created:** [July 26, 2018, 8:57am UTC](https://discuss.elastic.co/t/help-with-grok-patterns-to-parse-date-and-name-index-from-path/141721 "2018-07-26T08:57:10Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [July 26, 2018, 8:57am UTC](https://discuss.elastic.co/t/help-with-grok-patterns-to-parse-date-and-name-index-from-path/141721/1 "2018-07-26T08:57:10Z")

</div>

Hi, I kindly ask you some help with these Grok patterns.  
I have two requirements: the first is to extract the date from `path` and use it to name the Elasticsearch index. The second is to parse a date with a strange format.

Given that the `path` is this: `/usr/share/logstash/logs/file_report_20180726_0730.csv`  
I want to name the index `logstash-2018.07.26`

In the filter section, I have used this Grok filter:

```
grok {
    match => { "path" => %{GREEDYDATA}/file_report_%{INT:file_date}_%{INT}.csv }
}

```

But this produces `file_date = 20180726`, while I would like to have `file_date = 2018.07.26` in order to do as follows in the ouput section:

```
output {
    elasticsearch {
	    hosts => ["elasticsearch:9200"]
	    index => "logstash-%{file_date}"
    }
}

```

Moreover, I have a date field which I need to parse. This field is formatted like this: `2018-07-08 09:49:43.868+02`

Edit: one more question. Is it possible to match a date even if two events could have a different format? For instance, `2018-07-08 09:49:43.868` and `2018-07-08 09:49:43`

Is it possible to parse it with the date filter plugin or is it necessary to use Grok?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 26, 2018, 12:56pm UTC](https://discuss.elastic.co/t/help-with-grok-patterns-to-parse-date-and-name-index-from-path/141721/2 "2018-07-26T12:56:32Z")

</div>

You could transform filedate using

```
mutate { gsub => ["filedate", "(....)(..)(..)", "\1.\2.\3"] }

```

You should use a date filter to parse those date. For example

```
date { match => ["somefield", "yyyy-MM-dd HH:mm:ss.SSS", "yyyy-MM-dd HH:mm:ss"] }
```

---

<div class="post-metadata">

**Author:** ![espogian](https://avatars.discourse-cdn.com/v4/letter/e/4491bb/32.png) [@espogian](https://discuss.elastic.co/u/espogian)\
**Post date:** [July 26, 2018, 1:35pm UTC](https://discuss.elastic.co/t/help-with-grok-patterns-to-parse-date-and-name-index-from-path/141721/3 "2018-07-26T13:35:04Z")

</div>

Thank you!!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2018, 1:35pm UTC](https://discuss.elastic.co/t/help-with-grok-patterns-to-parse-date-and-name-index-from-path/141721/4 "2018-08-23T13:35:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
