# Logstash output - set output file name

**URL:** <https://discuss.elastic.co/t/logstash-output-set-output-file-name/264023>\
**Category:** Logstash\
**Created:** [February 11, 2021, 1:56pm UTC](https://discuss.elastic.co/t/logstash-output-set-output-file-name/264023 "2021-02-11T13:56:55Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![liavsh](https://avatars.discourse-cdn.com/v4/letter/l/48db29/32.png) [@liavsh](https://discuss.elastic.co/u/liavsh)\
**Post date:** [February 11, 2021, 1:56pm UTC](https://discuss.elastic.co/t/logstash-output-set-output-file-name/264023/1 "2021-02-11T13:56:55Z")

</div>

Hi

I'm new to logstash...  
I'm using logstash to stream logfiles from AWS MSK Kafka to AWS S3 bucket.

I FAIL setting the output filename inside the bucket.  
I was able to set the folder that will hold the output file.

here's my logstash.cohfig file

```auto
input {
    kafka {
        bootstrap_servers => "${FILEBEAT_KAFKA_HOSTS}"
        topics => ["${TOPIC_PROVIDED_BY_ECS}"]
        tags => "${TOPIC_PROVIDED_BY_ECS}"
    }
}

output {
   s3 {
     bucket => "${DESTINATION_NAME}"
     size_file => "${FILE_SIZE_IN_BYTES}"
     region => "${DESTINATION_CHARACTERISTIC_NAME}"
     prefix => "${TOPIC_PROVIDED_BY_ECS}/"
   }
}

```

I read in logstash docs that the output file name will consist (among other) from the "tags" value:  
section "S3 output file"  
in [S3 output plugin | Logstash Reference [7.11] | Elastic](https://www.elastic.co/guide/en/logstash/7.11/plugins-outputs-s3.html#plugins-outputs-s3-size_file)

I tried using:  
tags =\> "{TOPIC\_PROVIDED\_BY\_ECS}" tags =\> ["{TOPIC\_PROVIDED\_BY\_ECS}"]  
tags =\> ["justAname"]

But It did not help.

My goal is that the file name will be part of the output file name  
E.G when TOPIC\_PROVIDED\_BY\_ECS=PINKFLOYD  
Then the file name will be something like:  
ls.s3.0de8cfe6290-8fab-4691-910c-c4befed0da5c.2021-02-11T12.30.PINKFLOYD.part81.txt

Prefaerable with more readable date:  
ls.s3.0d8cfe6290-8fab-4691-910c-c4befed0da5c.2021-02-11\_12-31-16-323.PINKFLOYD.part81.txt

Any Ideas ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 11, 2021, 8:18pm UTC](https://discuss.elastic.co/t/logstash-output-set-output-file-name/264023/2 "2021-02-11T20:18:37Z")

</div>

> [@liavsh](#):
>
> `tags => "${TOPIC_PROVIDED_BY_ECS}"`

That will add an entry to the [tags] array [containing](https://www.elastic.co/guide/en/logstash/current/environment-variables.html) the value of the environment variable TOPIC\_PROVIDED\_BY\_ECS. It seems unlikely that you want that.

If you want to know what topic an event was read from take a look at the [decorate\_events](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-kafka.html#plugins-inputs-kafka-decorate_events) option on the kafka input. Note that the documentation of that contradicts itself.

If you want the prefix to be set to the topic you would use

```
prefix => "%{[@metadata][kafka][topic]}"

```

---

<div class="post-metadata">

**Author:** ![liavsh](https://avatars.discourse-cdn.com/v4/letter/l/48db29/32.png) [@liavsh](https://discuss.elastic.co/u/liavsh)\
**Post date:** [February 14, 2021, 10:16am UTC](https://discuss.elastic.co/t/logstash-output-set-output-file-name/264023/3 "2021-02-14T10:16:10Z")

</div>

Hi Badger

Thanks a lot for your reply 🙂 !

When I use the prefix, I'm only able to control the PATH to the output file name and not the output FILE NAME itself. At least , this is what I saw when I was 'playing' with the configuration file.  
My goal is to control the out put file name.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 14, 2021, 5:46pm UTC](https://discuss.elastic.co/t/logstash-output-set-output-file-name/264023/4 "2021-02-14T17:46:03Z")

</div>

> [@liavsh](#):
>
> My goal is to control the out put file name.

The [code](https://github.com/logstash-plugins/logstash-output-s3/blob/f0a74700d4f3ebe7936e165455179a6a46ca361d/lib/logstash/outputs/s3/temporary_file_factory.rb#L66) does not support that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 14, 2021, 5:46pm UTC](https://discuss.elastic.co/t/logstash-output-set-output-file-name/264023/5 "2021-03-14T17:46:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
