# How to get filebeat source date field?

**URL:** <https://discuss.elastic.co/t/how-to-get-filebeat-source-date-field/159489>\
**Category:** Beats\
**Created:** [December 5, 2018, 8:54am UTC](https://discuss.elastic.co/t/how-to-get-filebeat-source-date-field/159489 "2018-12-05T08:54:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![aabababba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aabababba/32/36732_2.png) [@aabababba](https://discuss.elastic.co/u/aabababba)\
**Post date:** [December 5, 2018, 8:54am UTC](https://discuss.elastic.co/t/how-to-get-filebeat-source-date-field/159489/1 "2018-12-05T08:54:57Z")

</div>

like this

/home/api/log/20181205/20181205\_152840.log

I want "20181205" can out put date field in logstash.

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 5, 2018, 3:44pm UTC](https://discuss.elastic.co/t/how-to-get-filebeat-source-date-field/159489/2 "2018-12-05T15:44:06Z")

</div>

The file name is forwarded in the `source` field to Logstash. You can use grok/dissect to extract it. Not sure if `date` filter can parse it in Logstash. At worst you will have to use the ruby filter.

---

<div class="post-metadata">

**Author:** ![aabababba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aabababba/32/36732_2.png) [@aabababba](https://discuss.elastic.co/u/aabababba)\
**Post date:** [December 6, 2018, 1:36am UTC](https://discuss.elastic.co/t/how-to-get-filebeat-source-date-field/159489/3 "2018-12-06T01:36:49Z")

</div>

I set this ,but can't have data.

```auto
grok {
        match => {
            "source" => "%{GREEDYDATA:sth1}/%{YEAR}%{MONTHNUM}%{MONTHDAY}%/{GREEDYDATA:sth2}"
             }
          }

```

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 6, 2018, 1:30pm UTC](https://discuss.elastic.co/t/how-to-get-filebeat-source-date-field/159489/4 "2018-12-06T13:30:28Z")

</div>

Better store the date in a field. Plus, it seems you have a syntax error in the last section.

e.g. capturing complete date into a field named `ts`:

```auto
grok {
        match => {
            "source" => "%{GREEDYDATA:sth1}/%{PATH_TS:ts}/%{GREEDYDATA:sth2}"
         }
         pattern_definitions => {
           "PATH_TS" => "%{YEAR}%{MONTHNUM}%{MONTHDAY}"
         }

}

```

This gets you the fields `sth1`, `ts`, and `sth2`. You still must transform the `ts` field to a date.

---

<div class="post-metadata">

**Author:** ![aabababba](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aabababba/32/36732_2.png) [@aabababba](https://discuss.elastic.co/u/aabababba)\
**Post date:** [December 7, 2018, 1:56am UTC](https://discuss.elastic.co/t/how-to-get-filebeat-source-date-field/159489/5 "2018-12-07T01:56:40Z")

</div>

thanks,but 'ts' can't not get data, I use 'dissect', it work now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 4, 2019, 3:57am UTC](https://discuss.elastic.co/t/how-to-get-filebeat-source-date-field/159489/6 "2019-01-04T03:57:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
