# Logstash Output File - Add data in filename

**URL:** <https://discuss.elastic.co/t/logstash-output-file-add-data-in-filename/210545>\
**Category:** Logstash\
**Created:** [December 4, 2019, 1:44pm UTC](https://discuss.elastic.co/t/logstash-output-file-add-data-in-filename/210545 "2019-12-04T13:44:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![giorgiogale](https://avatars.discourse-cdn.com/v4/letter/g/278dde/32.png) [@giorgiogale](https://discuss.elastic.co/u/giorgiogale)\
**Post date:** [December 4, 2019, 1:44pm UTC](https://discuss.elastic.co/t/logstash-output-file-add-data-in-filename/210545/1 "2019-12-04T13:44:24Z")

</div>

Hi,

i would like to add the current date into the name of the file created by logstash process.  
The date isn't an information that i received in input, but i have to get it.

I had succeeded, adding the following code to the filter section:

> `ruby {code => "event.set('time_log',Time.now().strftime('%Y-%m-%d'));"}`

in output section:

> file {  
> path =\> "/dati/LOG\_JSON/ascc\_disp-%{time\_log}.log"  
> }

the file name is written correctly

> ascc\_disp-2019-12-04.log

but the value contained in the time\_log variable is also present in the json sent on queue kafka.

below is the complete output section:

> output {  
> kafka {  
> codec =\> json  
> topic\_id =\> "in.dispositivi"  
> acks =\> "0"  
> bootstrap\_servers =\> "xxx.xxx.xxx.xxx:9092"  
> security\_protocol =\> "SSL"  
> client\_id =\> "test"  
> ssl\_truststore\_location =\> "/dati/logstash/logstash-7.1.1/config/keystore.jks"  
> ....  
> ....  
> }
> 
> file {  
> path =\> "/dati/LOG\_JSON/ascc\_disp-%{time\_log}.log"  
> }  
> }

How can I use the variable only to construct the file name, and exclude it from the contents of the json I send to kafka?

thank you very much,

Giorgio

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 4, 2019, 3:27pm UTC](https://discuss.elastic.co/t/logstash-output-file-add-data-in-filename/210545/2 "2019-12-04T15:27:36Z")

</div>

If a field is nested inside [@metadata] then it is not sent with the rest of the event to the output, so replace [log\_time] with [@metadata][log\_time].

---

<div class="post-metadata">

**Author:** ![giorgiogale](https://avatars.discourse-cdn.com/v4/letter/g/278dde/32.png) [@giorgiogale](https://discuss.elastic.co/u/giorgiogale)\
**Post date:** [December 6, 2019, 9:02am UTC](https://discuss.elastic.co/t/logstash-output-file-add-data-in-filename/210545/3 "2019-12-06T09:02:08Z")

</div>

thank you so much @Badger for the suggestion.  
I tried it and it works.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2020, 9:02am UTC](https://discuss.elastic.co/t/logstash-output-file-add-data-in-filename/210545/4 "2020-01-03T09:02:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
