# How to extract file name from source vairable

**URL:** https://discuss.elastic.co/t/how-to-extract-file-name-from-source-vairable/74347
**Category:** Logstash
**Created:** [February 8, 2017, 9:29am UTC](https://discuss.elastic.co/t/how-to-extract-file-name-from-source-vairable/74347 "2017-02-08T09:29:55Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)
#### Post date: [February 8, 2017, 9:29am UTC](https://discuss.elastic.co/t/how-to-extract-file-name-from-source-vairable/74347/1 "2017-02-08T09:29:55Z")

</div>

HI Team,  
I need to extract the source field, when i process im getting grok parse failure please find the belwo image for your reference,

 ![](https://us1.discourse-cdn.com/elastic/original/2X/a/a68d29f973f92a7a15863d32c9d31e485a35e135.png)  
Im using below grok pattern,

%{PATH}/%{UUID:requestFileId}

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [February 8, 2017, 9:39am UTC](https://discuss.elastic.co/t/how-to-extract-file-name-from-source-vairable/74347/2 "2017-02-08T09:39:50Z")

</div>

That doesn't work because the filename isn't a UUID because it begins with "U" (and ends with "\_Request.xml" but is it happens that doesn't matter here).

Use `%{PATH}/%{UUID:requestFileId}` instead of `%{PATH}/U%{UUID:requestFileId}` and things should work better.

---

<div class="post-metadata">

### Author: ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)
#### Post date: [February 8, 2017, 9:46am UTC](https://discuss.elastic.co/t/how-to-extract-file-name-from-source-vairable/74347/3 "2017-02-08T09:46:14Z")

</div>

Its not working, Im getting same error. I want to extract this value also from this input,

/beep/envs/beepq/config/ddoa/logs/old/0a5d3ad4-421c-49bd-b05f-c83e869e526f\_Request.xml

Expected Result: 0a5d3ad4-421c-49bd-b05f-c83e869e526f

but im getting parse failure

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [February 8, 2017, 9:52am UTC](https://discuss.elastic.co/t/how-to-extract-file-name-from-source-vairable/74347/4 "2017-02-08T09:52:30Z")

</div>

> Its not working, Im getting same error.

With the exact input string you gave in your example or with the file named 0a5d3ad4-421c-49bd-b05f-c83e869e526f\_Request.xml?

---

<div class="post-metadata">

### Author: ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)
#### Post date: [February 8, 2017, 10:37am UTC](https://discuss.elastic.co/t/how-to-extract-file-name-from-source-vairable/74347/5 "2017-02-08T10:37:34Z")

</div>

Actually im processing one xml please find the result of that file,

![](https://us1.discourse-cdn.com/elastic/original/2X/b/b2f5a646baff2048e38fd736918fa5fb0f76d3a9.png)

I want to extract this value "0a5d3ad4-421c-49bd-b05f-c83e869e526f" from source field how can i perform that. Please help on that

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [February 8, 2017, 10:47am UTC](https://discuss.elastic.co/t/how-to-extract-file-name-from-source-vairable/74347/6 "2017-02-08T10:47:53Z")

</div>

Never post screenshots if you can use copy/paste.

I don't know why `%{PATH}` as in your previous example doesn't work, but the grok expression `/%{UUID:requestFileId}_Request.xml$` works fine.

---

<div class="post-metadata">

### Author: ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)
#### Post date: [February 8, 2017, 10:52am UTC](https://discuss.elastic.co/t/how-to-extract-file-name-from-source-vairable/74347/7 "2017-02-08T10:52:57Z")

</div>

"offset" =\> 0,  
"count" =\> 1,  
"input\_type" =\> "log",  
"source" =\> "/beep/envs/beepq/config/ddoa/logs/fault/0ef47a3d-7dc6-4ccd-b49e-fad22018ccf6\_Request.xml",  
"tags" =\> [  
[0] "beats\_input\_codec\_plain\_applied",  
[1] "\_grokparsefailure"  
],  
"@timestamp" =\> 2017-02-08T07:19:03.829Z,  
"file\_type" =\> "ProcessRepairOrder",  
"@version" =\> "1",  
"beat" =\> {  
"hostname" =\> "vmtlesdq01",  
"name" =\> "vmtlesdq01"  
},  
"host" =\> "vmtlesdq01",  
"fingerprint" =\> "18c5809fa1cf7208b25fdfc0052fe997f8af2cb3",  
"fields" =\> nil

---

<div class="post-metadata">

### Author: ![Ganesh2303](https://avatars.discourse-cdn.com/v4/letter/g/57b2e6/32.png) [@Ganesh2303](https://discuss.elastic.co/u/Ganesh2303)
#### Post date: [February 8, 2017, 10:55am UTC](https://discuss.elastic.co/t/how-to-extract-file-name-from-source-vairable/74347/8 "2017-02-08T10:55:05Z")

</div>

This is what i got from grok debugger

 ![](https://us1.discourse-cdn.com/elastic/original/2X/e/eb149351c726ddb4e06b306e21d1d6187036aa65.png)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 8, 2017, 10:55am UTC](https://discuss.elastic.co/t/how-to-extract-file-name-from-source-vairable/74347/9 "2017-03-08T10:55:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
