# Logstash Conf | Extracting Filename from Path

**URL:** <https://discuss.elastic.co/t/logstash-conf-extracting-filename-from-path/303818>\
**Category:** Logstash\
**Created:** [May 3, 2022, 10:38am UTC](https://discuss.elastic.co/t/logstash-conf-extracting-filename-from-path/303818 "2022-05-03T10:38:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![srii](https://avatars.discourse-cdn.com/v4/letter/s/9de0a6/32.png) [@srii](https://discuss.elastic.co/u/srii)\
**Post date:** [May 3, 2022, 10:38am UTC](https://discuss.elastic.co/t/logstash-conf-extracting-filename-from-path/303818/1 "2022-05-03T10:38:53Z")

</div>

I am trying to setup Logstash to feed Elasticsearch. In course, I've created the following conf file that seem to work nicely:

```auto
input {
  beats {
    port => 5044
  }
  
  file {
    path => "C:/f1/f2/Logs/f3/LocalHost#base#iway_2022-03-28T10_45_15.log"
  }
}

filter {
  grok {
    match => {
      "message" => [
        ".%{TIMESTAMP_ISO8601:timeStamp}. %{LOGLEVEL:loglevel} .(W.)%{DATA:thread}.%{INT:thread_pool}. %{GREEDYDATA:msgbody}",
        ".%{TIMESTAMP_ISO8601:timeStamp}. %{LOGLEVEL:loglevel} .%{DATA:thread}. %{GREEDYDATA:msgbody}"      
      ]
    }
  }
}

output {
  elasticsearch {
    hosts => ["https://localhost:9200"]
    index => "iway_logs"
    user => "elastic"
    password => "something"
    cacert => "C:\f1\f2\logstash-8.1.3\config\cert\elasticsearch_http_ca.crt"
  }
}

```

I have been trying to add two new fields but unsuccessful so far. Following is the current version of the conf file after several revises.

```auto
input {
  beats {
    port => 5044
  }
  
  file {
    path => "C:/f1/f2/Logs/f3/LocalHost#base#iway_2022-03-28T10_45_15.log"
  }
}

filter {
  grok {
    match => {
      "message" => [
        ".%{TIMESTAMP_ISO8601:timeStamp}. %{LOGLEVEL:loglevel} .(W.)%{DATA:thread}.%{INT:thread_pool}. %{GREEDYDATA:msgbody}",
        ".%{TIMESTAMP_ISO8601:timeStamp}. %{LOGLEVEL:loglevel} .%{DATA:thread}. %{GREEDYDATA:msgbody}"      
      ]
    }
  }
  grok {
        match => { 
            "path" => "%{GREEDYDATA}/%{GREEDYDATA:filename}\.log"
            }
  }
  mutate {
        split => { "filename" => "#" }
        add_field => { "serverName" => "%{[filename][0]}" }
        add_field => { "configName" => "%{[filename][1]}" }
  }
}

output {
  elasticsearch {
    hosts => ["https://localhost:9200"]
    index => "iway_logs"
    user => "elastic"
    password => "something"
    cacert => "C:\f1\f2\logstash-8.1.3\config\cert\elasticsearch_http_ca.crt"
  }
}

```

The result of new fields namely, serverName and configName, always reports the raw expression as opposed to an evaluated output. Could someone help? TIA.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 3, 2022, 4:23pm UTC](https://discuss.elastic.co/t/logstash-conf-extracting-filename-from-path/303818/2 "2022-05-03T16:23:50Z")

</div>

> [@srii](#):
>
> The result of new fields namely, serverName and configName, always reports the raw expression as opposed to an evaluated output.

That is telling you that the [filename] field does not exist. Do you really have a [path] field? With ECS (enabled by default now) I would not expect that field to be called that.

---

<div class="post-metadata">

**Author:** ![srii](https://avatars.discourse-cdn.com/v4/letter/s/9de0a6/32.png) [@srii](https://discuss.elastic.co/u/srii)\
**Post date:** [May 3, 2022, 4:36pm UTC](https://discuss.elastic.co/t/logstash-conf-extracting-filename-from-path/303818/3 "2022-05-03T16:36:14Z")

</div>

That was indeed the case. I had to apply the complete context path of the field, that is, [log][file][path]. Thanks for your feedback.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2022, 4:37pm UTC](https://discuss.elastic.co/t/logstash-conf-extracting-filename-from-path/303818/4 "2022-05-31T16:37:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
