# Need help with grok

**URL:** <https://discuss.elastic.co/t/need-help-with-grok/355674>\
**Category:** Logstash\
**Created:** [March 19, 2024, 4:01am UTC](https://discuss.elastic.co/t/need-help-with-grok/355674 "2024-03-19T04:01:02Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![roman-tasi](https://avatars.discourse-cdn.com/v4/letter/r/7ea924/32.png) [@roman-tasi](https://discuss.elastic.co/u/roman-tasi)\
**Post date:** [March 19, 2024, 4:01am UTC](https://discuss.elastic.co/t/need-help-with-grok/355674/1 "2024-03-19T04:01:02Z")

</div>

I need to perform a grok on the `directory` field with example value:  
`C:\Users\takuya\Desktop\_Summary presentation\references`

Where the `Desktop` value is pulled out and saved as a new field containing the `Desktop` value.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 19, 2024, 9:29am UTC](https://discuss.elastic.co/t/need-help-with-grok/355674/2 "2024-03-19T09:29:42Z")

</div>

Do you always need a value on 3rd position? What would be the field named?  
You can use split instead grok.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [March 19, 2024, 10:27am UTC](https://discuss.elastic.co/t/need-help-with-grok/355674/3 "2024-03-19T10:27:46Z")

</div>

```auto
input {
  generator { "message" => 'C:\Users\takuya\Desktop\_Summary presentation\references'
	   count => 1 }
 
} 

filter {
	 #dissect { mapping => { "message" => "%{disk}\%{dir1}\%{dir2}\%{_dir3}\%{dir4}\%{dir5}" } }
	 dissect { mapping => { "message" => "%{}\%{}\%{}\%{dir3}\%{}\%{}" } }

    grok { 
      #match => { "message" => "%{WORD:gdisk}\:\\%{DATA:gdir1}\\%{DATA:gdir2}\\%{DATA:gdir3}\\%{DATA:_gdir4}\\%{GREEDYDATA:gdir5}" }
      match => { "message" => "%{WORD}\:\\%{DATA}\\%{DATA}\\%{DATA:gdir3}\\%{DATA}\\%{GREEDYDATA}" }
    }
	
 	mutate { copy => { "message" => "[@metadata][path]"} }
 	mutate { gsub => ["[@metadata][path]", "[\\]", '/' ] }

    mutate { split => { "[@metadata][path]" => "/" }
    add_field => { "dirname" => "%{[@metadata][path][3]}"}
    }
 
}

output {
    stdout {codec => rubydebug }
}

```

Result:

```auto
{
       "message" => "C:\\Users\\takuya\\Desktop\\_Summary presentation\\references",
         "gdir3" => "Desktop",
          "dir3" => "Desktop",
       "dirname" => "Desktop"
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 16, 2024, 10:28am UTC](https://discuss.elastic.co/t/need-help-with-grok/355674/4 "2024-04-16T10:28:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
