# Sending changing log (name) to ELK

**URL:** <https://discuss.elastic.co/t/sending-changing-log-name-to-elk/73535>\
**Category:** Logstash\
**Created:** [February 1, 2017, 3:01pm UTC](https://discuss.elastic.co/t/sending-changing-log-name-to-elk/73535 "2017-02-01T15:01:25Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Yzord](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yzord/32/44824_2.png) [@Yzord](https://discuss.elastic.co/u/Yzord)\
**Post date:** [February 1, 2017, 3:01pm UTC](https://discuss.elastic.co/t/sending-changing-log-name-to-elk/73535/1 "2017-02-01T15:01:25Z")

</div>

I have a little problem. I want to send a logfile with the name "firewall-01-02-2017.log" to my ELK server, but this file is changing every month to for instance "firewall-01-03-2017.log" etc.

So i thought it would be better to use another format in my logstash-forwarder config and i thought this one would be ok:

> firewall-[0-3][0-9]-[0-1][0-9]-2[0-1][1-2][0-9].log

But it isn't doing much. My logstash-forwarder error log shows me this:

> 2017/02/01 15:44:33.166923 Waiting for 1 prospectors to initialise  
> 2017/02/01 15:44:33.167089 All prospectors initialised with 0 states to persist  
> 2017/02/01 15:44:33.167195 Setting trusted CA from file: /etc/pki/tls/certs/logstash-forwarder.crt  
> 2017/02/01 15:44:33.176126 Connecting to [145._._._]:5043 (145._._._)  
> 2017/02/01 15:44:33.273000 Connected to 145._._.\*

So, it is connected, but apparently it isn't liking the format i used, but i would not know what format it wants to have. Anyone played with this?

---

<div class="post-metadata">

**Author:** ![Yzord](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yzord/32/44824_2.png) [@Yzord](https://discuss.elastic.co/u/Yzord)\
**Post date:** [February 1, 2017, 5:16pm UTC](https://discuss.elastic.co/t/sending-changing-log-name-to-elk/73535/2 "2017-02-01T17:16:46Z")

</div>

Hmm, i just read that LSF isn't supported anymore, but my ELK stack is configured with it. Hopefully someone wants to help me with this issue ☹

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 1, 2017, 5:36pm UTC](https://discuss.elastic.co/t/sending-changing-log-name-to-elk/73535/3 "2017-02-01T17:36:23Z")

</div>

That kind of pattern isn't supported. Only basic shell wildcards like ? and \* are allowed, so try firewall-??-??-????.log or just firewall-\*.log.

---

<div class="post-metadata">

**Author:** ![Yzord](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yzord/32/44824_2.png) [@Yzord](https://discuss.elastic.co/u/Yzord)\
**Post date:** [February 1, 2017, 5:58pm UTC](https://discuss.elastic.co/t/sending-changing-log-name-to-elk/73535/4 "2017-02-01T17:58:16Z")

</div>

Thank you very much for your reply. Will test it out tomorrow when i'm at work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 1, 2017, 5:58pm UTC](https://discuss.elastic.co/t/sending-changing-log-name-to-elk/73535/5 "2017-03-01T17:58:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
