# Split filepath to a new field

**URL:** <https://discuss.elastic.co/t/split-filepath-to-a-new-field/319657>\
**Category:** Logstash\
**Created:** [November 23, 2022, 12:42pm UTC](https://discuss.elastic.co/t/split-filepath-to-a-new-field/319657 "2022-11-23T12:42:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![nestro](https://avatars.discourse-cdn.com/v4/letter/n/c57346/32.png) [@nestro](https://discuss.elastic.co/u/nestro)\
**Post date:** [November 23, 2022, 12:42pm UTC](https://discuss.elastic.co/t/split-filepath-to-a-new-field/319657/1 "2022-11-23T12:42:53Z")

</div>

Hi! I use Filebeat on a central Syslog server which collects logs from all network devices. Filebeat is configured to collect the logs (which are arrenged by days in the month) from this server and sends them to Logstash.

The log.file.path fileld's value is the following: /var/log/remote/device name/.

I would like to split the device name from the log.file.path field and make a new field for this which will be the device name field. And later visualize in Kibana.

I didn't found anything similar to this so far. Thank you for in advance!

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 23, 2022, 2:21pm UTC](https://discuss.elastic.co/t/split-filepath-to-a-new-field/319657/2 "2022-11-23T14:21:45Z")

</div>

Is this you looking for?

```auto
    mutate { add_field => { "devicename" => "%{[log][file][path]}" } }
    mutate{ gsub => ["devicename", '/var/log/remote/', ""] }
    mutate{ gsub => ["devicename", '[/]', "" ] }

```

Also is possible by grok

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [November 23, 2022, 2:51pm UTC](https://discuss.elastic.co/t/split-filepath-to-a-new-field/319657/3 "2022-11-23T14:51:56Z")

</div>

Another option is split and take whatever is on the 4th position.

```auto
    mutate { copy => { "[log][file][path]" => "[@metadata][path]"}}
    mutate { split => { "[@metadata][path]" => "/" } }
    mutate { add_field => { "devicename" => "%{[@metadata][path][4]}"}}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 21, 2022, 2:52pm UTC](https://discuss.elastic.co/t/split-filepath-to-a-new-field/319657/4 "2022-12-21T14:52:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
