# Problem indexing the year

**URL:** <https://discuss.elastic.co/t/problem-indexing-the-year/217870>\
**Category:** Logstash\
**Created:** [February 4, 2020, 8:02pm UTC](https://discuss.elastic.co/t/problem-indexing-the-year/217870 "2020-02-04T20:02:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Ay00b\_B](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ay00b_b/32/46158_2.png) [@Ay00b\_B](https://discuss.elastic.co/u/Ay00b_B)\
**Post date:** [February 4, 2020, 8:02pm UTC](https://discuss.elastic.co/t/problem-indexing-the-year/217870/1 "2020-02-04T20:02:09Z")

</div>

Hello, I am new to this whole ELK thing. Im an intern working on indexing a bunch of syslogs into elastic using logstash. The only problem is that the logs do not contain the year which I also want to index for each mapping. The year is only available on the file name. I am using the stdin plugin to read the logs into logstash since they are .gz files. I am aware I can use the file plugin with the read mode but this, to my understanding, deletes the log and relogs it even with the log setting. This is not okay with my superiors. My question is, what would be the best way to get the year from the file name and add it to each mapping. My current config is below.

```
input {
    stdin {
    }
}
filter {
     grok {
    match => {"message" => "%{SYSLOGTIMESTAMP:timestamp}\s+[0-9\.\/]+\s+dhcpd\[[0-9]+\]:\s+(DHCPACK) %{WORD} %{IP:ipaddress} %{WORD} %{MAC:macaddress} %{GREEDYDATA}"}
    match => {"message" => "%{SYSLOGTIMESTAMP:timestamp}\s+[0-9\.\/]+\s+dhcpd\[[0-9]+\]:\s+(DHCPACK) %{WORD} %{IP:ipaddress} \(%{MAC:macaddress}\) %{GREEDYDATA}"}
 }
}

output{
if "_grokparsefailure" in [tags] {
  } else {
elasticsearch {
     hosts => "http://localhost:9200"
     index => "dhcp"
}

  }
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 4, 2020, 8:55pm UTC](https://discuss.elastic.co/t/problem-indexing-the-year/217870/2 "2020-02-04T20:55:31Z")

</div>

If I had to do that I would do something like

```
for F in ... ; do
    gunzip -c $F | awk -v F=$F '{print F $0}' | logstash ...
done

```

to prefix every line with the filename.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 3, 2020, 8:55pm UTC](https://discuss.elastic.co/t/problem-indexing-the-year/217870/3 "2020-03-03T20:55:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
