# How do i add custom field based on filebeat input 's glob path?

**URL:** <https://discuss.elastic.co/t/how-do-i-add-custom-field-based-on-filebeat-input-s-glob-path/375526>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 6, 2025, 2:31pm UTC](https://discuss.elastic.co/t/how-do-i-add-custom-field-based-on-filebeat-input-s-glob-path/375526 "2025-03-06T14:31:23Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shreesh\_Narayanan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shreesh_narayanan/32/87312_2.png) [@Shreesh\_Narayanan](https://discuss.elastic.co/u/Shreesh_Narayanan)\
**Post date:** [March 6, 2025, 2:31pm UTC](https://discuss.elastic.co/t/how-do-i-add-custom-field-based-on-filebeat-input-s-glob-path/375526/1 "2025-03-06T14:31:23Z")

</div>

Hello,

I have a requirement , where i need to derive values based on the input path

example - i have a log file on a partition

format - /app/shared/1.1.1.1\_webserver\_ticket#1.log

From the above path , i need to extract the IP (1.1.1.1), component (webserver) and ticket (ticket#1) . My filebeat.yml looks like this

```auto

  # Paths that should be crawled and fetched. Glob based paths.
  paths:
    - /app/shared/*webserver_comp1.log
    - /app/shared/*webserver_comp2.log

```

Now the logstash config is written to fetch these details via grok

```auto
filter {
  grok {
    match => { "path" => "%{IP:machineip}_%{NOTSPACE:component}_%{NOTSPACE:ticket}" }
  }
}

```

How do i add a field based on the input glob pattern on filebeats' input section and pass it along to logstash ? Should i use the processor ? would that work based on each glob pattern ?
