# Logstash regex pattern for a windows path

**URL:** <https://discuss.elastic.co/t/logstash-regex-pattern-for-a-windows-path/322790>\
**Category:** Logstash\
**Created:** [January 10, 2023, 6:22am UTC](https://discuss.elastic.co/t/logstash-regex-pattern-for-a-windows-path/322790 "2023-01-10T06:22:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![ShubhamKumarJena](https://avatars.discourse-cdn.com/v4/letter/s/b782af/32.png) [@ShubhamKumarJena](https://discuss.elastic.co/u/ShubhamKumarJena)\
**Post date:** [January 10, 2023, 6:22am UTC](https://discuss.elastic.co/t/logstash-regex-pattern-for-a-windows-path/322790/1 "2023-01-10T06:22:33Z")

</div>

Hello Elastic community,

I am trying to use a if condition for my logstash filter for a windows path but not sure about the delimiter and correct syntax.

Here is my complete windows directory " R:\I3\IC\Logs\Sabio\_Elk\_Logs\amit1.txt " and I just need Sabio\_elk\_logs to be the value for my if condition.

I tried `if [log][file][path] =~ \\Sabio_elk_logs\` but it didn't work.

Can somebody throw some light on this regex pattern especially for windows path.

Kind regards,  
Shubham

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2023, 6:23am UTC](https://discuss.elastic.co/t/logstash-regex-pattern-for-a-windows-path/322790/2 "2023-02-07T06:23:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
