# Regarding timestamp index from log file name

**URL:** <https://discuss.elastic.co/t/regarding-timestamp-index-from-log-file-name/176184>\
**Category:** Logstash\
**Created:** [April 10, 2019, 9:32am UTC](https://discuss.elastic.co/t/regarding-timestamp-index-from-log-file-name/176184 "2019-04-10T09:32:34Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kalyan\_MB](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kalyan_mb/32/42974_2.png) [@Kalyan\_MB](https://discuss.elastic.co/u/Kalyan_MB)\
**Post date:** [April 10, 2019, 9:32am UTC](https://discuss.elastic.co/t/regarding-timestamp-index-from-log-file-name/176184/1 "2019-04-10T09:32:34Z")

</div>

Hi,

Problem: need to read time stamp from the input file name (filebeat ) from logstash filter.

input file name name format:  
-rw-r--r-- 1 root root 204 Apr 3 15:22 free\_data\_09\_09\_13\_20.txt  
-rw-r--r-- 1 root root 204 Apr 3 15:22 free\_data\_09\_09\_13\_10.txt  
-rw-r--r-- 1 root root 204 Apr 3 15:22 free\_data\_09\_09\_13\_00.txt

------ free\_data\_DD\_MM\_hh\_mm (date\_Month\_hour\_min)

now i want to read this time stamp from the input file name and create an index along with file content, which i will use later to plot graph against time stamp vs file-data-values.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 10, 2019, 12:18pm UTC](https://discuss.elastic.co/t/regarding-timestamp-index-from-log-file-name/176184/2 "2019-04-10T12:18:28Z")

</div>

Does this help?

```
    grok { match => { "someField" => "free_data_(?<ts>[0-9_]+).txt" } }
    date { match => ["ts", "dd_MM_HH_mm"] }

```

You do not have a year in your timestamp, so the date filter will guess, and sometimes you will not like its guess. There are issues for that [here](https://github.com/logstash-plugins/logstash-filter-date/issues/51) and [here](https://github.com/logstash-plugins/logstash-filter-date/issues/100).

---

<div class="post-metadata">

**Author:** ![Kalyan\_MB](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kalyan_mb/32/42974_2.png) [@Kalyan\_MB](https://discuss.elastic.co/u/Kalyan_MB)\
**Post date:** [April 10, 2019, 4:14pm UTC](https://discuss.elastic.co/t/regarding-timestamp-index-from-log-file-name/176184/3 "2019-04-10T16:14:41Z")

</div>

facing this problem..  
2019-04-03T20:42:54.626+0530 INFO log/harvester.go:216 Harvester started for file: /home/vankata/190\_APS\_QUALIFICATION/kalyan\_elk\_logs/free\_data\_11\_09\_02\_30.txt  
2019-04-03T20:42:54.626+0530 INFO prospector/prospector.go:121 Prospector ticker stopped  
2019-04-03T20:42:54.626+0530 INFO log/prospector.go:411 Scan aborted because prospector stopped.  
2019-04-03T20:42:54.626+0530 INFO prospector/prospector.go:121 Prospector ticker stopped  
2019-04-03T20:42:54.626+0530 INFO prospector/prospector.go:138 Stopping Prospector: 8728499415371259904  
2019-04-03T20:42:54.626+0530 INFO prospector/prospector.go:121 Prospector ticker stopped  
2019-04-03T20:42:54.626+0530 INFO log/harvester.go:216 Harvester started for file: /home/vankata/190\_APS\_QUALIFICATION/kalyan\_elk\_logs/free\_data\_11\_09\_10\_40.txt

filebeat version: filebeat-6.2.4

Note: tried to delete registry files by using clean\_\* command couldn't succeed though

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 10, 2019, 6:03pm UTC](https://discuss.elastic.co/t/regarding-timestamp-index-from-log-file-name/176184/4 "2019-04-10T18:03:42Z")

</div>

That is a filebeat question and you should ask in that forum.

---

<div class="post-metadata">

**Author:** ![Kalyan\_MB](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kalyan_mb/32/42974_2.png) [@Kalyan\_MB](https://discuss.elastic.co/u/Kalyan_MB)\
**Post date:** [April 11, 2019, 2:58am UTC](https://discuss.elastic.co/t/regarding-timestamp-index-from-log-file-name/176184/5 "2019-04-11T02:58:58Z")

</div>

ah yes!, this is logstash forum. thanks @Badger

---

<div class="post-metadata">

**Author:** ![Kalyan\_MB](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kalyan_mb/32/42974_2.png) [@Kalyan\_MB](https://discuss.elastic.co/u/Kalyan_MB)\
**Post date:** [April 11, 2019, 9:38am UTC](https://discuss.elastic.co/t/regarding-timestamp-index-from-log-file-name/176184/6 "2019-04-11T09:38:10Z")

</div>

@Badger, used the filter in logstash.conf as below looks like its not solving problem.

* * *

input {  
beats {  
port =\> 5044  
}  
}

filter {

grok { match =\> { "someField" =\> "free\_data\_(?[0-9\_]+).txt" } }  
date { match =\> ["ts", "dd\_MM\_HH\_mm"] }  
if [message] =~ /Mem:/ {  
dissect { mapping =\> {'message' =\> '%{mem\_type-\>} %{total\_mem-\>} %{used\_mem-\>} %{free\_mem-\>} %{shared\_mem-\>} %{cache\_mem-\>} %{availablemem}'} }  
} else if [message] =~ /Swap:/ {  
dissect { mapping =\> {'message' =\> '%{mem\_type-\>} %{total\_mem-\>} %{used\_mem-\>} %{free\_mem-\>}'} }  
}

}

output {  
if [service\_name] == "cfx" {  
elasticsearch  
{  
#path =\> "/var/log/sdl\_logs/%{vnf\_id}/%{vm\_type}/%{instance\_id}/%{service\_name}/%{app\_name}\_%{+yyyy-MM-dd-HH}.log"  
#codec =\> line { format =\> "%{message}" }  
#gzip =\> true  
hosts =\> ["[http://x.x.x.x:9200](http://x.x.x.x:9200)"]  
index =\> "freedata"

* * *

because after index pattern i cant see timestamp(ts) in discover page

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/c/bc54c3d0d92eb62c468df58b0874268f0aa1686a.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2019, 9:38am UTC](https://discuss.elastic.co/t/regarding-timestamp-index-from-log-file-name/176184/7 "2019-05-09T09:38:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
