# Some newbie questions file path and message replacement

**URL:** https://discuss.elastic.co/t/some-newbie-questions-file-path-and-message-replacement/159847
**Category:** Logstash
**Created:** [December 7, 2018, 5:40am UTC](https://discuss.elastic.co/t/some-newbie-questions-file-path-and-message-replacement/159847 "2018-12-07T05:40:11Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![alexsamad](https://avatars.discourse-cdn.com/v4/letter/a/f9ae1b/32.png) [@alexsamad](https://discuss.elastic.co/u/alexsamad)
#### Post date: [December 7, 2018, 5:40am UTC](https://discuss.elastic.co/t/some-newbie-questions-file-path-and-message-replacement/159847/1 "2018-12-07T05:40:11Z")

</div>

Hi  
extracting part of the path from source

I found this

> [@Extracting particular folder from the path and adding that to a field](https://discuss.elastic.co/t/extracting-particular-folder-from-the-path-and-adding-that-to-a-field/142277):
>
> Hi Guys, I need help to fetch particular folder from the path and assign the same to a different field. path ==\> /var/mqm/qmgrs/FOLDER\_NEEDED/errors/\*.log. I need to extract FOLDER\_NEEDED and assign it to a field for every message. Thanks.

And it seems to say what I want to do, but I am not sure how to implement

I have filebeat setup to send to a logstash input

I'm using grok, i've got  
grok {  
match =\> ["message" , "%{TIMESTAMP\_ISO8601:timestamp} (?[.\*]) %{LOGLEVEL:loglevel} %{GREEDYDATA:message}"]

}

all my source files names should be like

/path1/path2/path3/path4/

I am interested in getting path4 into a file name

this is what i saw from the message  
grok { match =\> ["message", "^/[^/]+/[^/]+/[^/]+/(?[^/]+)" ] }  
grok { match =\> ["message", "/(?[^/]+)/[^/]+/[^/]+$" ] }

what do i need to add to my code to extract path4. even to add to that lets say all the paths are like

/var/log/abc/\<path i'm interested in\>/  
so I'm guessing  
grok { match =\> ["message", "^/var/log+/(?[^/]+)" ] }

does this mean I get a variable called dir1 which has the info I am after ?

also

```
match => ["message" , "%{TIMESTAMP_ISO8601:timestamp} (?<thread>\[.*\]) %{LOGLEVEL:loglevel} %{GREEDYDATA:message}"]

```

the last bit adds the "rest" of the message as message[1]. doesn't save it in message[0]

how can i get {GREEDYDATA:message} to replace the message variable ?

thanks

edit

I'm thinking  
grok { match =\> ["message", "^/var/log+/(?[^/]+)" ] } should be  
grok { match =\> ["source", "^/var/log+/(?[^/]+)" ] }

---

<div class="post-metadata">

### Author: ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)
#### Post date: [December 7, 2018, 5:46am UTC](https://discuss.elastic.co/t/some-newbie-questions-file-path-and-message-replacement/159847/2 "2018-12-07T05:46:40Z")

</div>

My recommendation is to use the dissect filter instead of grok for parsing your file path.

---

<div class="post-metadata">

### Author: ![alexsamad](https://avatars.discourse-cdn.com/v4/letter/a/f9ae1b/32.png) [@alexsamad](https://discuss.elastic.co/u/alexsamad)
#### Post date: [December 7, 2018, 10:45am UTC](https://discuss.elastic.co/t/some-newbie-questions-file-path-and-message-replacement/159847/3 "2018-12-07T10:45:03Z")

</div>

could you maybe give an example ??

also any hint on my my %{GREEDYDATA:message} is added to message[1] and not message[0]

---

<div class="post-metadata">

### Author: ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)
#### Post date: [December 7, 2018, 3:47pm UTC](https://discuss.elastic.co/t/some-newbie-questions-file-path-and-message-replacement/159847/4 "2018-12-07T15:47:07Z")

</div>

Dissect info [here](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dissect.html)

---

<div class="post-metadata">

### Author: ![alexsamad](https://avatars.discourse-cdn.com/v4/letter/a/f9ae1b/32.png) [@alexsamad](https://discuss.elastic.co/u/alexsamad)
#### Post date: [December 7, 2018, 8:50pm UTC](https://discuss.elastic.co/t/some-newbie-questions-file-path-and-message-replacement/159847/5 "2018-12-07T20:50:03Z")

</div>

Hi

Thanks, not sure I understand - could you provide an example of inside and outside ?

---

<div class="post-metadata">

### Author: ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)
#### Post date: [December 7, 2018, 9:19pm UTC](https://discuss.elastic.co/t/some-newbie-questions-file-path-and-message-replacement/159847/6 "2018-12-07T21:19:08Z")

</div>

Nevermind...I just thought of why it's like that. You're reusing the field name "message". Use another name and then either remove the original "message" field or overwrite it with your new field name. i.e. {GREEDYDATA:new\_message}

You can use the common option "remove\_field" in all filters and the mutate filter to update/replace/rename your message field.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [January 4, 2019, 9:19pm UTC](https://discuss.elastic.co/t/some-newbie-questions-file-path-and-message-replacement/159847/7 "2019-01-04T21:19:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
