# Log\_file\_path

**URL:** <https://discuss.elastic.co/t/log-file-path/267727>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 18, 2021, 10:27pm UTC](https://discuss.elastic.co/t/log-file-path/267727 "2021-03-18T22:27:25Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![christos\_zivlas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christos_zivlas/32/85776_2.png) [@christos\_zivlas](https://discuss.elastic.co/u/christos_zivlas)\
**Post date:** [March 18, 2021, 10:27pm UTC](https://discuss.elastic.co/t/log-file-path/267727/1 "2021-03-18T22:27:25Z")

</div>

Hi i am using filebeat on windows to get some application logs. Messages are harvest using a wildcard path. messages coming in do not contain the path of the log, is there a way to place such a field in the log message?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [March 31, 2021, 5:12pm UTC](https://discuss.elastic.co/t/log-file-path/267727/2 "2021-03-31T17:12:43Z")

</div>

Hi @christos_zivlas, welcome to discuss 🙂

If you are using the `log` input, log path should be in the event, in the `log.file.path` field.

---

<div class="post-metadata">

**Author:** ![christos\_zivlas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christos_zivlas/32/85776_2.png) [@christos\_zivlas](https://discuss.elastic.co/u/christos_zivlas)\
**Post date:** [April 4, 2021, 8:04pm UTC](https://discuss.elastic.co/t/log-file-path/267727/3 "2021-04-04T20:04:31Z")

</div>

Hi, this is what happens on linux filebeat, the path shows as you describe but for windows filebeat this is not the case? Is there way to configure filebeat for windows to retrieve that info?

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [April 6, 2021, 11:10am UTC](https://discuss.elastic.co/t/log-file-path/267727/4 "2021-04-06T11:10:57Z")

</div>

What inputs are you using in Windows? If you are using the `log` input, it should also fill this field.

---

<div class="post-metadata">

**Author:** ![christos\_zivlas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christos_zivlas/32/85776_2.png) [@christos\_zivlas](https://discuss.elastic.co/u/christos_zivlas)\
**Post date:** [April 6, 2021, 5:25pm UTC](https://discuss.elastic.co/t/log-file-path/267727/5 "2021-04-06T17:25:09Z")

</div>

Hi jsoriano, i am using windows filebeat version 7.11 and graylog 3.1.4 and log input. I was expecting to see log.file.path field as i do when i get logs from linux machines with file beat. i am using a log input as the configuration below

```auto
# Needed for Graylog
fields_under_root: true
fields.collector_node_id: ${sidecar.nodeName}
fields.gl2_source_collector: ${sidecar.nodeId}
fields.source: ${sidecar.nodeName}

output.logstash:
   hosts: ["172.17.1.213:5044"]
path:
  data: C:\Program Files\Graylog\sidecar\cache\filebeat\data
  logs: C:\Program Files\Graylog\sidecar\logs

filebeat.inputs:

- input_type: log
  enabled: true
  #ignore_older: 48h
  #close_eof: true
  tail_files: true
  tags: 
    - gxsas2
  paths:
  
  - D:\as2\icomas2logs\gxs\*\*\*

```

i am not really sure what i am doing wrong

---

<div class="post-metadata">

**Author:** ![christos\_zivlas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christos_zivlas/32/85776_2.png) [@christos\_zivlas](https://discuss.elastic.co/u/christos_zivlas)\
**Post date:** [April 6, 2021, 5:44pm UTC](https://discuss.elastic.co/t/log-file-path/267727/6 "2021-04-06T17:44:36Z")

</div>

![image](https://us1.discourse-cdn.com/elastic/original/3X/0/1/01fa44808a35d9a713198edb1d8cf260da4f767b.png)

---

<div class="post-metadata">

**Author:** ![jsoriano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsoriano/32/27920_2.png) [@jsoriano](https://discuss.elastic.co/u/jsoriano)\
**Post date:** [April 7, 2021, 4:22pm UTC](https://discuss.elastic.co/t/log-file-path/267727/7 "2021-04-07T16:22:48Z")

</div>

Do you have access to the original event as sent by filebeat? From this screenshot I see that some field names are modified (for example `beat_name` instead of `beat.name`).

---

<div class="post-metadata">

**Author:** ![christos\_zivlas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christos_zivlas/32/85776_2.png) [@christos\_zivlas](https://discuss.elastic.co/u/christos_zivlas)\
**Post date:** [April 7, 2021, 6:56pm UTC](https://discuss.elastic.co/t/log-file-path/267727/8 "2021-04-07T18:56:55Z")

</div>

Hi jsoriano, no fields were modified...this is the original configuration as created by graylog in sidecar section. Not sure if and how to access the original event. Not sure how filebeat for windows differs from filebeat for linux. I have 2 windows filebeat. Filebeat is running is running on top of sidecar if it makes any difference. Is there a chance this is not supported on filebeat for windows?

---

<div class="post-metadata">

**Author:** ![christos\_zivlas](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christos_zivlas/32/85776_2.png) [@christos\_zivlas](https://discuss.elastic.co/u/christos_zivlas)\
**Post date:** [April 8, 2021, 7:06pm UTC](https://discuss.elastic.co/t/log-file-path/267727/9 "2021-04-08T19:06:22Z")

</div>

Hi I think manage to find a solution first of all fixing the \_ . Then realised that i can assign log.file.path to a field. Now my question is, how can i add a custom field with in filebeat configuration? Do i need a processor?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 12, 2021, 12:29am UTC](https://discuss.elastic.co/t/log-file-path/267727/10 "2021-04-12T00:29:09Z")

</div>

U can use the set processor to add a new field.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 10, 2021, 2:29am UTC](https://discuss.elastic.co/t/log-file-path/267727/11 "2021-05-10T02:29:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
