# I can't get a directory name added as a field in Logstash and Kibana

**URL:** <https://discuss.elastic.co/t/i-cant-get-a-directory-name-added-as-a-field-in-logstash-and-kibana/74518>\
**Category:** Logstash\
**Created:** [February 9, 2017, 2:27pm UTC](https://discuss.elastic.co/t/i-cant-get-a-directory-name-added-as-a-field-in-logstash-and-kibana/74518 "2017-02-09T14:27:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hoagieben](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hoagieben/32/15366_2.png) [@hoagieben](https://discuss.elastic.co/u/hoagieben)\
**Post date:** [February 9, 2017, 2:27pm UTC](https://discuss.elastic.co/t/i-cant-get-a-directory-name-added-as-a-field-in-logstash-and-kibana/74518/1 "2017-02-09T14:27:14Z")

</div>

Hi again.

I have a structure within Logstash running in Docker of /opt/logs/CUSTOMERNAME/SERVERNAME/SystemOut\*.log

I want to have SERVERNAME and CUSTOMERNAME as fields in Kibana but it doesn't work for me.

Below is the config as it is now

input {  
file {  
path =\> ["/opt/logs/_/_/SystemOut\*.log"]  
start\_position =\> "beginning"  
type =\> "websphere"  
# important! logstash read only logs from files touched the last 24 hours  
# 8640000 = 100 days  
sincedb\_path =\> "/dev/null"  
ignore\_older =\> "8640000"  
}  
}  
filter {  
if [type] =~ "websphere" {  
grok {  
match =\> ["source", "%{GREEDYDATA}/%{GREEDYDATA:server\_name}/SystemOut.log"]  
}  
grok {  
match =\> ["message", "[%{DATA:wastimestamp} %{WORD:tz}] %{BASE16NUM:was\_threadID} (?\<was\_shortname\>\b[A-Za-z0-9$]{2,}\b) %{SPACE}%{WORD:was\_loglevel}%{SPACE} %{GREEDYDATA:was\_  
msg}"]  
}  
grok {  
match =\> ["was\_msg", "(?\<was\_errcode\>[A-Z0-9]{9,10})[:,\s\s]%{GREEDYDATA:was\_msg}"]  
overwrite =\> ["was\_msg"]  
tag\_on\_failure =\> []  
}  
translate {  
field =\> "tz"  
destination =\> "tz\_num"  
dictionary =\> [  
"CET", "+0100",  
"CEST", "+0200",  
"EDT", "-0400",  
"GMT", "+0000"  
]  
}  
translate {  
field =\> "was\_errcode"  
destination =\> "was\_application"  
regex =\> "true"  
exact =\> "true"  
dictionary =\> [  
"CLFRW", "Search",  
"CLFRA", "Activities",  
"CLFRS", "Blogs",  
"CLFRL", "Bookmarks",  
"CLFRK", "Common",  
"CLFRM", "Communities",  
"EJPVJ", "Files",  
"CLFRV", "Forums",  
"CLFRQ", "Homepage",  
"CLFRP", "Installer",  
"CLFRO", "Configuration",  
"CLFRR", "Notifications",  
"CLFNF", "Portlet",  
"CLFRT", "FedSearch",  
"CLFWX", "News",  
"CLFWY", "Event",  
"CLFWZ", "Widget",  
"CLFRN", "Profiles",  
"CLFWY", "User",  
"EJPIC", "Portal",  
"EJPVJ", "Wikis",  
"ADMS", "Websphere",  
"SECJ", "Security"  
]  
}  
mutate {  
replace =\> ['timestamp', '%{wastimestamp} %{tz\_num}']  
}  
date{  
match =\> ["timestamp", "MM/dd/YY HH:mm:ss:SSS Z", "M/d/YY HH:mm:ss:SSS Z"]  
tag\_on\_failure =\> []  
}  
mutate {  
remove\_field =\> ['tz', 'tz\_num', 'wastimestamp']  
}  
}  
}  
output {  
elasticsearch {  
hosts =\> ["elasticsearch:9200"]  
}  
stdout { codec =\> rubydebug }  
}

I have tried

}  
filter {  
if [type] =~ "websphere" {  
grok {  
match =\> ["source", "/opt/logs/%{GREEDYDATA:customer\_name}/%{GREEDYDATA:server\_name}/SystemOut.log"]  
}

As well as

}  
filter {  
if [type] =~ "websphere" {  
grok {  
match =\> ["path", "/opt/logs/%{GREEDYDATA:customer\_name}/%{GREEDYDATA:server\_name}/SystemOut.log"]  
}

And

}  
filter {  
if [type] =~ "websphere" {  
grok {  
match =\> ["source", "/opt/logs/%{DATA:customer\_name}/%{DATA:server\_name}/SystemOut.log"]  
}

and

}  
filter {  
if [type] =~ "websphere" {  
grok {  
match =\> ["path", "/opt/logs/%{WORD:customer\_name}/%{WORD:server\_name}/SystemOut.log"]  
}

Since I'm not sure whether it should be WORD or DATA or path or source I'm trying things a bit randomly.

Can anyone help with what the syntax should be please?

This is what is in Logstash with the current config

{  
"was\_loglevel" =\> "O",  
"was\_msg" =\> " lzwcompression=enabled, showhiddentext=no, gridcols=100, suppressfontcolor=no, strictdtd=no, collapsewhitespace=no, processgeneratedtext=yes, defaultinputcharset=utf8, charset=utf8, pagesize=0, extractembeddedformat=off, javascripttabs=no, exportendpage=1, charbyteorder=template, jpegquality=100, graphicsizemethod=smooth, fiflags=SCCUT\_FI\_NORMAL, flavor=msie40, gifinterlace=yes, graphicskipsize=5, labelwpcells=no, wellformed=no, jpegcompression=enabled, exportstartpage=1, noxmldeclarationflag=no, graphicbuffersize=0, gridwrap=TRUE}",  
"message" =\> "[1/9/17 14:57:25:448 GMT] 00000511 SystemOut O {fallbackformat=FI\_UTF8, pstylenamesflag=no, preferoitrendering=true, gridrows=5000, graphictype=jpeg, simplestylenames=no, suppressfontsize=no, embeddingsflag=yes, graphicwidthlimit=1000, unmappablechar=0x002A, nosourceformatting=yes, suppressfontface=no, separategraphicsbuffer=yes, textbuffersize=0, graphicheightlimit=1000, genbulletsandnums=yes, graphicoutputdpi=96, labelssdbcells=no, exepath=/opt/IBM/Connections/data/local/search/stellent/dcs/oiexport/exporter, xmldefmethod=NONE, fallbackfont=Arial, maxurllength=0, whattoexport=all, graphicsizelimit=0, preventgraphicoverlap=no, gridadvance=down, outputid=FI\_SEARCHTEXT, lzwcompression=enabled, showhiddentext=no, gridcols=100, suppressfontcolor=no, strictdtd=no, collapsewhitespace=no, processgeneratedtext=yes, defaultinputcharset=utf8, charset=utf8, pagesize=0, extractembeddedformat=off, javascripttabs=no, exportendpage=1, charbyteorder=template, jpegquality=100, graphicsizemethod=smooth, fiflags=SCCUT\_FI\_NORMAL, flavor=msie40, gifinterlace=yes, graphicskipsize=5, labelwpcells=no, wellformed=no, jpegcompression=enabled, exportstartpage=1, noxmldeclarationflag=no, graphicbuffersize=0, gridwrap=TRUE}",  
"type" =\> "websphere",  
"was\_shortname" =\> "SystemOut",  
"tags" =\> [  
[0] "\_grokparsefailure"  
],  
"was\_threadID" =\> "00000511",  
"path" =\> "/opt/logs/portal/InfraCluster\_server1/SystemOut\_17.01.11\_22.39.17.log",  
"@timestamp" =\> 2017-01-09T14:57:25.448Z,  
"@version" =\> "1",  
"host" =\> "f2730df8227c",  
"was\_errcode" =\> "SEARCHTEXT",  
"timestamp" =\> "1/9/17 14:57:25:448 +0000"  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 9, 2017, 3:02pm UTC](https://discuss.elastic.co/t/i-cant-get-a-directory-name-added-as-a-field-in-logstash-and-kibana/74518/2 "2017-02-09T15:02:48Z")

</div>

The field with the path is named `path` but you're attempting to parse `source`.

Unrelated, but don't use multiple DATA or GREEDYDATA patterns in the same expression. In this case you can just drop the first use of GREEDYDATA as you don't need it.

---

<div class="post-metadata">

**Author:** ![hoagieben](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hoagieben/32/15366_2.png) [@hoagieben](https://discuss.elastic.co/u/hoagieben)\
**Post date:** [February 14, 2017, 10:11am UTC](https://discuss.elastic.co/t/i-cant-get-a-directory-name-added-as-a-field-in-logstash-and-kibana/74518/3 "2017-02-14T10:11:21Z")

</div>

I fixed this using the following configuration. I have left in the remmed out lines to show what I tried.

input {  
file {  
path =\> ["/opt/logs/_/_/SystemOut\*.log"]  
start\_position =\> "beginning"  
type =\> "websphere"  
# important! logstash read only logs from files touched the last 24 hours  
# 8640000 = 100 days  
sincedb\_path =\> "/dev/null"  
ignore\_older =\> "8640000"  
}  
}  
filter {  
if [type] =~ "websphere" {  
grok {  
#match =\> ["path", "%{GREEDYDATA}/%{GREEDYDATA:server\_name}/SystemOut\*.log"]  
#match =\> ["path", "/opt/logs/_/%{GREEDYDATA:server\_name}/SystemOut_.log"]  
#match =\> ["path", "/opt/logs/_/(?\<server\_name\>[^/]+)/SystemOut_.log" ]  
match =\> ["path", "/opt/logs/%{WORD:customer}/%{WORD:server\_name}"]  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2017, 10:11am UTC](https://discuss.elastic.co/t/i-cant-get-a-directory-name-added-as-a-field-in-logstash-and-kibana/74518/4 "2017-03-14T10:11:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
