# Logstash Input-Path as Index

**URL:** https://discuss.elastic.co/t/logstash-input-path-as-index/304030
**Category:** Logstash
**Created:** [May 5, 2022, 12:27pm UTC](https://discuss.elastic.co/t/logstash-input-path-as-index/304030 "2022-05-05T12:27:28Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![Robsen\_Inc](https://avatars.discourse-cdn.com/v4/letter/r/d26b3c/32.png) [@Robsen\_Inc](https://discuss.elastic.co/u/Robsen_Inc)
#### Post date: [May 5, 2022, 12:27pm UTC](https://discuss.elastic.co/t/logstash-input-path-as-index/304030/1 "2022-05-05T12:27:28Z")

</div>

Hi Community,

I would like to use the Path as an index.

The question has been asked many times in different forums, but unfortunately the solutions presented do not work for me.

Maybe you can help me.  
Specifically, I want to read in my entire folder of records with:  
`path => "/logs/inputdata/cardets/*"`  
and then find in Elasticsearch the indexes related to the files. like "ta1-cadets-e3-official-1.json.4".

attached my (now hard-coded) pipeline config:

```auto
input{
  file {
     path => "/logs/inputdata/cardets/ta1-cadets-e3-official-1.json.4"
     start_position => "beginning" 
     codec => "json"
     type => cardets
     sincedb_path => "/dev/null"
  }
}
filter {
  mutate {
    add_field => {
      "event.dataset" => "cadets"
    }
  }
}
output {
  elasticsearch {
    hosts => "${ELASTICSEARCH_HOSTS}"
    user => "${ELASTICSEARCH_USERNAME}"
    password => "${ELASTIC_PASSWORD}"
    index => "ta1-cadets-e3-official-1.json.4"
    ssl => true
    cacert => '/usr/share/logstash/config/certs/ca/ca.crt' 
  }
}

```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [May 5, 2022, 4:06pm UTC](https://discuss.elastic.co/t/logstash-input-path-as-index/304030/2 "2022-05-05T16:06:36Z")

</div>

In recent versions the index option to the Elasticsearch output is ignored because [ILM](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-ilm) is enabled.

If you disable that you could use `index => "%{[log][file][path]}"` (assuming ECS is enabled), although using a large number of small indexes is very inefficient.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [June 2, 2022, 4:07pm UTC](https://discuss.elastic.co/t/logstash-input-path-as-index/304030/3 "2022-06-02T16:07:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
