# I want to add a field with filename

**URL:** https://discuss.elastic.co/t/i-want-to-add-a-field-with-filename/114049
**Category:** Logstash
**Created:** [January 4, 2018, 9:25am UTC](https://discuss.elastic.co/t/i-want-to-add-a-field-with-filename/114049 "2018-01-04T09:25:08Z")
**Posts on this page:** 9
**Page:** 1

<div class="post-metadata">

### Author: ![Asier\_Saluena](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Asier\_Saluena](https://discuss.elastic.co/u/Asier_Saluena)
#### Post date: [January 4, 2018, 9:25am UTC](https://discuss.elastic.co/t/i-want-to-add-a-field-with-filename/114049/1 "2018-01-04T09:25:08Z")

</div>

Hi you all, i'm starting a project with elk stack and we have few domains working on the same machine, which sends his apache logs to elk. I want to extract the filename to filter by this field on kibana.  
I'm trying something like the following code:

> ```
> filter {
> if [type] == "apache-access" {
> grok {
> match => { "message" => "%{COMBINEDAPACHELOG}" }
> match => { "message" => "%{GREEDYDATA}/%{GREEDYDATA:filename}\.es_access_log"}
> }
> mutate {
> remove_field => ["message"]
> }
> }
> }
> 
> ```

When I look at Kibana I find out that I have a field called source which contains whole path to the file but It's impossible to me to extract filename from here

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [January 6, 2018, 10:25am UTC](https://discuss.elastic.co/t/i-want-to-add-a-field-with-filename/114049/2 "2018-01-06T10:25:04Z")

</div>

Grok filters stop evaluating expressions when they get a match, so if the COMBINEDAPACHELOG expression matches the other one won't be tried at all. Secondly, if the file path is stored in the `source` field you obviously need to tell the grok filter to match _that_ field and not `message`.

---

<div class="post-metadata">

### Author: ![Asier\_Saluena](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Asier\_Saluena](https://discuss.elastic.co/u/Asier_Saluena)
#### Post date: [January 8, 2018, 7:54am UTC](https://discuss.elastic.co/t/i-want-to-add-a-field-with-filename/114049/3 "2018-01-08T07:54:44Z")

</div>

So, I have to apply another grok filter for this document-type, is this correct?

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [January 8, 2018, 8:20am UTC](https://discuss.elastic.co/t/i-want-to-add-a-field-with-filename/114049/4 "2018-01-08T08:20:38Z")

</div>

Yes.

---

<div class="post-metadata">

### Author: ![Asier\_Saluena](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Asier\_Saluena](https://discuss.elastic.co/u/Asier_Saluena)
#### Post date: [January 8, 2018, 8:59am UTC](https://discuss.elastic.co/t/i-want-to-add-a-field-with-filename/114049/5 "2018-01-08T08:59:13Z")

</div>

Thanks for your help, I´m gonna try it.

---

<div class="post-metadata">

### Author: ![Asier\_Saluena](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Asier\_Saluena](https://discuss.elastic.co/u/Asier_Saluena)
#### Post date: [January 12, 2018, 7:57am UTC](https://discuss.elastic.co/t/i-want-to-add-a-field-with-filename/114049/6 "2018-01-12T07:57:32Z")

</div>

I have been doing tests during this week with this configuration and still does not show the filename, I dont know why is it incorrect.  
First config file:

> ```
> filter {
> if [type] == "apache-access" {
> grok {
> match => { "message" => "%{COMBINEDAPACHELOG}" }
> }
> mutate {
> remove_field => ["message"]
> }
> geoip {
> source => "clientip"
> }
> }
> }
> 
> ```

Second config file:

> ```
> filter {
> if [%{host}] == "***" {
> grok {
> match => { "source" => "%{GREEDYDATA}/%{GREEDYDATA:filename}\.es_access_log"}
> }
> }
> }
> 
> ```

---

<div class="post-metadata">

### Author: ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)
#### Post date: [January 18, 2018, 9:56pm UTC](https://discuss.elastic.co/t/i-want-to-add-a-field-with-filename/114049/7 "2018-01-18T21:56:27Z")

</div>

> ```
> if [%{host}] == "***" {
> 
> ```

`[host]`, not `[%{host}]`. I assume "\*\*\*" is your way of censoring the hostname.

---

<div class="post-metadata">

### Author: ![Asier\_Saluena](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Asier\_Saluena](https://discuss.elastic.co/u/Asier_Saluena)
#### Post date: [January 24, 2018, 7:53am UTC](https://discuss.elastic.co/t/i-want-to-add-a-field-with-filename/114049/8 "2018-01-24T07:53:06Z")

</div>

Thanks! Now is working properly.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [February 21, 2018, 7:53am UTC](https://discuss.elastic.co/t/i-want-to-add-a-field-with-filename/114049/9 "2018-02-21T07:53:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
