# Question about parsing log.file.path field

**URL:** <https://discuss.elastic.co/t/question-about-parsing-log-file-path-field/360872>\
**Category:** Logstash\
**Created:** [June 5, 2024, 3:55pm UTC](https://discuss.elastic.co/t/question-about-parsing-log-file-path-field/360872 "2024-06-05T15:55:23Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Borja](https://avatars.discourse-cdn.com/v4/letter/b/ed8c4c/32.png) [@Borja](https://discuss.elastic.co/u/Borja)\
**Post date:** [June 5, 2024, 3:55pm UTC](https://discuss.elastic.co/t/question-about-parsing-log-file-path-field/360872/1 "2024-06-05T15:55:23Z")

</div>

Hi all,

we are trying to ingest from filebeat some differents apache logs from diffent apps and different directories.  
So we have this input structure (this are the log.file.path fields ingested)  
/home/E879365/logs/app1\_azure/app1.log  
/home/E879365/logs/app2\_was/app2.log  
/home/E879365/logs/app3\_jboss/app3.log

we need to parse the log.file.path field and get the app qualifier (in this case we nedd app1\_azure, app2\_was adn app3\_jboss)

we have configured this on logstash:

```auto
filter {
    grok {
       match => ["log.file.path","/home/E879365/logs/%{DATA:application}/%{GREEDYDATA:resto}"]
        }
}

```

bu we are not able to get this working....we see docs on elastic but we don't get the application field ingested in any case.

in the docs ingested we see this grokparsefailure on the tags field:  
tags on every single doc ingested:  
[apache, test, test, beats\_input\_codec\_plain\_applied, \_grokparsefailure]

we have tried with this, as we have seen a similiar question on the forum, bu it didn't worked either:

```auto
filter {
    grok {
       match => ["[log][file][path]","/home/E879365/logs/%{DATA:application}/%{GREEDYDATA:resto}"]
        }
}

```

On the grok debugger on elastic we see the correct fields parsed:

input: /home/E879365/logs/app1\_azure/app1.log  
grok pattern: /home/E879365/logs/%{DATA:application}/%{GREEDYDATA:resto}  
result:

{  
"application": "app1\_azure",  
"resto": "app1.log"  
}

what are we missing or doing wrong?

best regards

Borja

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [June 5, 2024, 5:33pm UTC](https://discuss.elastic.co/t/question-about-parsing-log-file-path-field/360872/2 "2024-06-05T17:33:01Z")

</div>

Check [this](https://discuss.elastic.co/t/extract-folder-name-as-field-in-logstash/305026/7) and [this](https://discuss.elastic.co/t/need-help-with-grok/355674/3). Things are much simpler with the dissect plugin.

---

<div class="post-metadata">

**Author:** ![Borja](https://avatars.discourse-cdn.com/v4/letter/b/ed8c4c/32.png) [@Borja](https://discuss.elastic.co/u/Borja)\
**Post date:** [June 7, 2024, 10:21am UTC](https://discuss.elastic.co/t/question-about-parsing-log-file-path-field/360872/3 "2024-06-07T10:21:45Z")

</div>

Hi Rios!

Thanks for your answer. Links provided gave us the clue to find de solution.

As far as all the input machines were linux we configured logstash in this way:

```auto
    mutate {
            copy => {"[log][file][path]" => "filepath" }
           }
    mutate{
         split => { "filepath" => '/' }
         add_field => { "application.name" => '%{[filepath][4]}' }
          }

```

best regards

Borja

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [June 7, 2024, 7:35pm UTC](https://discuss.elastic.co/t/question-about-parsing-log-file-path-field/360872/4 "2024-06-07T19:35:19Z")

</div>

Depend on the case, sometimes is more suitable split, sometimes grok or dissect.

Thank you for your feedback.
