# Logstash - Get index name from filename

**URL:** <https://discuss.elastic.co/t/logstash-get-index-name-from-filename/213891>\
**Category:** Logstash\
**Created:** [January 6, 2020, 1:07pm UTC](https://discuss.elastic.co/t/logstash-get-index-name-from-filename/213891 "2020-01-06T13:07:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lubos\_Marek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lubos_marek/32/59043_2.png) [@Lubos\_Marek](https://discuss.elastic.co/u/Lubos_Marek)\
**Post date:** [January 6, 2020, 1:07pm UTC](https://discuss.elastic.co/t/logstash-get-index-name-from-filename/213891/1 "2020-01-06T13:07:15Z")

</div>

Hello,  
I am loading files by logstash and I would like to know if it possible to set index from filename.  
For example my files are:

system1-yyyyMMdd.csv (system1-20200106.csv)  
system2-yyyyMMdd.csv (system2-20200106.csv)

and I would like to create indexes with "system1" and "system2", so I need to separate the first part from the filename.

```
input {
  file {
    path => ["/usr/share/logstash/data1/*.csv"]
    start_position => "beginning"
  }
}
filter {
  csv {
    separator => ";"
    columns => ["datetime", "level", "statuscode", "message", "endpoint"]
  }
}
output {
  elasticsearch {
    hosts => ["http://host.docker.internal:9200"]
    index => "index"
  }
}
```

---

<div class="post-metadata">

**Author:** ![pjanzen](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pjanzen/32/13756_2.png) [@pjanzen](https://discuss.elastic.co/u/pjanzen)\
**Post date:** [January 6, 2020, 2:26pm UTC](https://discuss.elastic.co/t/logstash-get-index-name-from-filename/213891/2 "2020-01-06T14:26:06Z")

</div>

Hi,

Not with your current configuration. You could an input for each file and add a field that you can use in the index name.

```
input {
  file {
    path => ["/usr/share/logstash/data1/system1.csv"]
    start_position => "beginning"
    add_field => "system1"
  }
  file {
    path => ["/usr/share/logstash/data1/system2.csv"]
    start_position => "beginning"
    add_field => "system2"
  }
}
filter {
  csv {
    separator => ";"
    columns => ["datetime", "level", "statuscode", "message", "endpoint"]
  }
}

# Setup index name
filter {
    if [system1] {
        mutate { add_field => { "[@metadata][index_name]" => "system1-%{+YYYY.MM.dd}" } }
    } else if [system2] {
        mutate { add_field => { "[@metadata][index_name]" => "system2-%{+YYYY.MM.dd}" } }
    } else {
        mutate { add_field => { "[@metadata][index_name]" => "unknown-system-%{+YYYY.MM.dd}" } }
    }
}

output {
  elasticsearch {
    hosts => ["http://host.docker.internal:9200"]
    index => "%{[@metadata][index_name]}"
  }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 6, 2020, 5:09pm UTC](https://discuss.elastic.co/t/logstash-get-index-name-from-filename/213891/3 "2020-01-06T17:09:52Z")

</div>

The file input adds a path field to events. You want to extract everything between the last / in the path and the first - in that section, which is

```
grok { match => { "path" => "(?<[@metadata][filePrefix]>[^/\-]+)-[^/]+$" } }

```

then

```
 index => "%{[@metadata][filePrefix]}"
```

---

<div class="post-metadata">

**Author:** ![Lubos\_Marek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lubos_marek/32/59043_2.png) [@Lubos\_Marek](https://discuss.elastic.co/u/Lubos_Marek)\
**Post date:** [January 7, 2020, 10:13am UTC](https://discuss.elastic.co/t/logstash-get-index-name-from-filename/213891/5 "2020-01-07T10:13:35Z")

</div>

Thanks very much. It is working very well.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 4, 2020, 10:13am UTC](https://discuss.elastic.co/t/logstash-get-index-name-from-filename/213891/6 "2020-02-04T10:13:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
