# Logstash input Filter path

**URL:** <https://discuss.elastic.co/t/logstash-input-filter-path/150307>\
**Category:** Logstash\
**Created:** [September 28, 2018, 7:58am UTC](https://discuss.elastic.co/t/logstash-input-filter-path/150307 "2018-09-28T07:58:11Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rocky\_RK](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@Rocky\_RK](https://discuss.elastic.co/u/Rocky_RK)\
**Post date:** [September 28, 2018, 7:58am UTC](https://discuss.elastic.co/t/logstash-input-filter-path/150307/1 "2018-09-28T07:58:11Z")

</div>

I have a logstash.conf file where i'm defining two distinct path for two different type of logs one is for `system logs` and another is for `network logs`. However, these logs are being collected on the same directory location as `/scratch/rsyslog` where its creating an individual folder for each host before dumping the logs, for example ..

1. `/scratch/rsyslog/server01/messages.log`  
`/scratch/rsyslog/server02/messages.log` and so on for the **system logs**

2. For **network logs** its like:  
`/scratch/rsyslog/Sep/messages.log`

Below is the input Filter and path for both type of logs. now the problem is that i'm using wildcard to match to get all the names with `*` here `path => ["/scratch/rsyslog/*/messages.log"]` which gets everything.

```
input {
  file {
    path => ["/scratch/rsyslog/*/messages.log"]
    type => "syslog"
  }
  file {
    path => ["/scratch/rsyslog/Sep/messages.log"]
    type => "apic_logs"
  }
}

```

So, in the First path which is **system logs** i need that starts with lowercase letters which may include some numbers though like `server01`.

> Maybe i'm thinking `^[a-z0-9]`

Whereas in second path which is **network logs** i need to get where first letter startswith uppercase letter following lowercase (these are month names usually like i mentioned `Sep` , it gets changed itself on the month end).

> maybe \[1\].\* for second one

i'm looking to get a regex which can fit into this situation.  
any help will be much appreciated.

* * *

1. A-Z

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [September 28, 2018, 8:08pm UTC](https://discuss.elastic.co/t/logstash-input-filter-path/150307/2 "2018-09-28T20:08:52Z")

</div>

You should be aware that this is not a regex per se, it is a POSIX glob pattern [http://man7.org/linux/man-pages/man7/glob.7.html](http://man7.org/linux/man-pages/man7/glob.7.html)

---

<div class="post-metadata">

**Author:** ![Rocky\_RK](https://avatars.discourse-cdn.com/v4/letter/r/ed655f/32.png) [@Rocky\_RK](https://discuss.elastic.co/u/Rocky_RK)\
**Post date:** [September 29, 2018, 10:45am UTC](https://discuss.elastic.co/t/logstash-input-filter-path/150307/3 "2018-09-29T10:45:12Z")

</div>

@guyboertje, ah! thanks for the awakening call. So, does these globbing patterns can be used in the input filter path or any suggestion or work-around to my problem.  
Thnx mila anyways for the revert.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 27, 2018, 10:45am UTC](https://discuss.elastic.co/t/logstash-input-filter-path/150307/4 "2018-10-27T10:45:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
