# How to set log.file.path in dev tools

**URL:** <https://discuss.elastic.co/t/how-to-set-log-file-path-in-dev-tools/198094>\
**Category:** Kibana\
**Created:** [September 4, 2019, 6:41pm UTC](https://discuss.elastic.co/t/how-to-set-log-file-path-in-dev-tools/198094 "2019-09-04T18:41:22Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Fosiul\_Alam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fosiul_alam/32/43335_2.png) [@Fosiul\_Alam](https://discuss.elastic.co/u/Fosiul_Alam)\
**Post date:** [September 4, 2019, 6:41pm UTC](https://discuss.elastic.co/t/how-to-set-log-file-path-in-dev-tools/198094/1 "2019-09-04T18:41:22Z")

</div>

```auto
GET filebeat-*/_search
{
   "size":1000,
   "log.file.path":"*logfile.log",
   "query":{
      "bool":{
         "must":{
            "match":{
               "message":"'[COMMAND:LOG]' and '[COMMAND:1]'"
            }
         },
         "filter":{
            "range":{
               "@timestamp":{
                  "gte":"now-15m"
               }
            }
         }
      }
   }
}

```

I am trying to match only that log file defined in "log.file.path": "\*logfile.log",  
but it say

```auto
{
   "error":{
      "root_cause":[
         {
            "type":"parsing_exception",
            "reason":"Unknown key for a VALUE_STRING in [log.file.path].",
            "line":3,
            "col":20
         }
      ],
      "type":"parsing_exception",
      "reason":"Unknown key for a VALUE_STRING in [log.file.path].",
      "line":3,
      "col":20
   },
   "status":400
}

```

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [September 5, 2019, 6:01pm UTC](https://discuss.elastic.co/t/how-to-set-log-file-path-in-dev-tools/198094/2 "2019-09-05T18:01:33Z")

</div>

What is `log.file.path` in reference to? Is this a field in your index your wanting to reference or an Elasticsearch setting?

---

<div class="post-metadata">

**Author:** ![Fosiul\_Alam](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fosiul_alam/32/43335_2.png) [@Fosiul\_Alam](https://discuss.elastic.co/u/Fosiul_Alam)\
**Post date:** [September 5, 2019, 7:19pm UTC](https://discuss.elastic.co/t/how-to-set-log-file-path-in-dev-tools/198094/3 "2019-09-05T19:19:42Z")

</div>

Hi,  
Normally in Kibana discover tools i use this search  
log.file.path:_CONCOX.log_ And "[COMMAND:LOG]" AND "[POS:false]"

log.file.path is a filed . example

| **t** input.type | log |
| --- | --- |
| | |

**t** log.file.path /log/CONCOX.log

---

<div class="post-metadata">

**Author:** ![tylersmalley](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tylersmalley/32/8833_2.png) [@tylersmalley](https://discuss.elastic.co/u/tylersmalley)\
**Post date:** [September 5, 2019, 8:19pm UTC](https://discuss.elastic.co/t/how-to-set-log-file-path-in-dev-tools/198094/4 "2019-09-05T20:19:36Z")

</div>

For that, the query is going to look more like this:

```auto
GET filebeat-*/_search
{
   "size":1000,
   "query":{
      "bool":{
        "filter":[
            {
              "bool":{
                  "should":[
                    {
                        "match":{
                          "log.file.path":"CONCOX.log"
                        }
                    }
                  ],
                  "minimum_should_match":1
              }
            },
            {
              "bool":{
                  "filter":[
                    {
                        "multi_match":{
                          "type":"phrase",
                          "query":"[COMMAND:LOG]",
                          "lenient":true
                        }
                    },
                    {
                        "multi_match":{
                          "type":"phrase",
                          "query":"[POS:false]",
                          "lenient":true
                        }
                    }
                  ]
              }
            }
        ]
      }
   }
}

```

Here are the docs for the query DSL: [https://www.elastic.co/guide/en/elasticsearch/reference/current/query-filter-context.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/query-filter-context.html)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2019, 8:19pm UTC](https://discuss.elastic.co/t/how-to-set-log-file-path-in-dev-tools/198094/5 "2019-10-03T20:19:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
