# Parse path with file input in logstash

**URL:** <https://discuss.elastic.co/t/parse-path-with-file-input-in-logstash/104735>\
**Category:** Logstash\
**Created:** [October 20, 2017, 4:20pm UTC](https://discuss.elastic.co/t/parse-path-with-file-input-in-logstash/104735 "2017-10-20T16:20:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![bm1391](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bm1391](https://discuss.elastic.co/u/bm1391)\
**Post date:** [October 20, 2017, 4:20pm UTC](https://discuss.elastic.co/t/parse-path-with-file-input-in-logstash/104735/1 "2017-10-20T16:20:55Z")

</div>

Im throwing in some suricata logs through logstash and this works fine, but I'm wondering if there is a better way to separate and tag the log files...

```
> input {
> file {
> path => "/home/user/nfs/suricata/bronn/eve.json"
> codec => "json"
> start_position => "beginning"
> sincedb_path => "/dev/null"
> type => "suricata"
> }

```

As you can see, I'm using a nfs mount to store all of "eve.json" files from different computers. In this case, "bronn" is the specific computer. Suricata outputs its json with eve.json.

Filter:

```
  if [path] =~ "(?<![\w\d])bronn(?![\w\d])" {
    mutate {
      add_field => { "monitor-hostname" => "bronn-monitor" }
    }

```

Im wondering if there is a better way to define one path in the input section `"/home/user/nfs/suricata/*/*"` and then parse the path for the computer name so I can use it later on when adding a field.  
The way its working right now is fine but in the filter section, I would have to add a new conditional for each computer added, which requires restarting logstash and would get pretty large eventually.

Thank you

---

<div class="post-metadata">

**Author:** ![bm1391](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bm1391](https://discuss.elastic.co/u/bm1391)\
**Post date:** [October 20, 2017, 5:43pm UTC](https://discuss.elastic.co/t/parse-path-with-file-input-in-logstash/104735/2 "2017-10-20T17:43:14Z")

</div>

Was able to accomplish this with:

> ```
> path => "/home/user/nfs/suricata/*/*"
> 
> ```

filter{  
grok {  
match =\> {  
path =\> "%{GREEDYDATA}/%{GREEDYDATA:monitor-hostname}.json"  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 21, 2017, 9:19am UTC](https://discuss.elastic.co/t/parse-path-with-file-input-in-logstash/104735/3 "2017-10-21T09:19:48Z")

</div>

I strongly suggest you don't use two GREEDYDATA patterns like that. It's inefficient and could match incorrectly. I suggest this instead:

```
/(?<monitor-hostname>[^/]+)\.json$
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 18, 2017, 9:20am UTC](https://discuss.elastic.co/t/parse-path-with-file-input-in-logstash/104735/4 "2017-11-18T09:20:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
