# Logstash output csv index name

**URL:** <https://discuss.elastic.co/t/logstash-output-csv-index-name/128231>\
**Category:** Logstash\
**Created:** [April 16, 2018, 4:46pm UTC](https://discuss.elastic.co/t/logstash-output-csv-index-name/128231 "2018-04-16T16:46:24Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [April 16, 2018, 4:46pm UTC](https://discuss.elastic.co/t/logstash-output-csv-index-name/128231/1 "2018-04-16T16:46:25Z")

</div>

I'm using [Csv output plugin | Logstash Reference](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-csv.html#plugins-outputs-csv-path) to write events to file on disk.

snippet from my logstash configuration:

```
output {
  csv {
    fields => ["@timestamp","XXX","YYY","ZZZ"]
    path => "/tmp/XXX-%{+YYYY-MM-dd}.csv"
  }
}

```

Is there a way to incorporate `_index` name into file name somehow?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 16, 2018, 4:50pm UTC](https://discuss.elastic.co/t/logstash-output-csv-index-name/128231/2 "2018-04-16T16:50:48Z")

</div>

Is that a field? You can reference fields in the event using the [%{some\_field}](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html) notation.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [April 16, 2018, 4:54pm UTC](https://discuss.elastic.co/t/logstash-output-csv-index-name/128231/3 "2018-04-16T16:54:25Z")

</div>

`_index` is part of all docs.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 16, 2018, 5:09pm UTC](https://discuss.elastic.co/t/logstash-output-csv-index-name/128231/4 "2018-04-16T17:09:40Z")

</div>

Once they are docs, that's true, but you didn't say that you were pulling data out of elasticsearch 🙂 Set docinfo =\> true on the elasticsearch input and refer to %{[@metadata][\_index]} in the path string.

---

<div class="post-metadata">

**Author:** ![alexus](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/alexus/32/12696_2.png) [@alexus](https://discuss.elastic.co/u/alexus)\
**Post date:** [April 16, 2018, 7:13pm UTC](https://discuss.elastic.co/t/logstash-output-csv-index-name/128231/5 "2018-04-16T19:13:19Z")

</div>

yup, that's exactly what I was looking for)

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 14, 2018, 7:13pm UTC](https://discuss.elastic.co/t/logstash-output-csv-index-name/128231/6 "2018-05-14T19:13:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
