# Use part of the log files name for the index?

**URL:** <https://discuss.elastic.co/t/use-part-of-the-log-files-name-for-the-index/246366>\
**Category:** Logstash\
**Created:** [August 25, 2020, 11:30pm UTC](https://discuss.elastic.co/t/use-part-of-the-log-files-name-for-the-index/246366 "2020-08-25T23:30:14Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![hcker2000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hcker2000/32/74497_2.png) [@hcker2000](https://discuss.elastic.co/u/hcker2000)\
**Post date:** [August 25, 2020, 11:30pm UTC](https://discuss.elastic.co/t/use-part-of-the-log-files-name-for-the-index/246366/1 "2020-08-25T23:30:15Z")

</div>

I have my files all in the same directory names like such:

```auto
/var/log/apache2/testsite1.com_error.log
/var/log/apache2/testsite1.com_access.log
/var/log/apache2/subdomain.testsite1.com_error.log
/var/log/apache2/subdomain.testsite1.com_access.log

```

What I would like to do is have each of those get grouped into there own index. For example:

```auto
apache-testsite1.com-2020-08-02
apache-subdomain.testsite1.com-2020-08-02

```

Any thoughts on how to get this done? Here is my config file:

```auto
input {
  file {
    path => "/logs/apache2/*.log"
    sincedb_path => "/logstash/data/sincedb-apache-access"
  }
}

filter {
  if [path] =~ "access" {
    mutate { replace => { type => "apache_access" } }
    grok {
      match => { "message" => "%{COMBINEDAPACHELOG}" }
    }
    date {
      match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
    }
  } else if [path] =~ "error" {
    mutate { replace => { type => "apache_error" } }
  } else {
    mutate { replace => { type => "random_logs" } }
  }

  grok {
    match => { "path" => ["(?<domain>[a-zA-Z0-9-.]+(?=_))"] }
  }
}

output {
  elasticsearch { 
      hosts => ["elasticsearch:9200"]
      index => "apache-${domain}-%{+YYYY.MM.dd}"
  }
  # stdout { codec => rubydebug }
}

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [August 26, 2020, 1:01am UTC](https://discuss.elastic.co/t/use-part-of-the-log-files-name-for-the-index/246366/2 "2020-08-26T01:01:26Z")

</div>

A thoughtless solution is to have 1 file input per each log type. Then you can tag it add use that tag in the name.

---

<div class="post-metadata">

**Author:** ![hcker2000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hcker2000/32/74497_2.png) [@hcker2000](https://discuss.elastic.co/u/hcker2000)\
**Post date:** [August 26, 2020, 2:04pm UTC](https://discuss.elastic.co/t/use-part-of-the-log-files-name-for-the-index/246366/3 "2020-08-26T14:04:14Z")

</div>

So I solved this with the following changes:

Grok Line:

```auto
match => { "path" => "(?<domain>[a-zA-Z0-9-.]+(?=_))" }

```

Output index:

```auto
index => "apache-%{domain}-%{+YYYY.MM.dd}"

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 23, 2020, 2:04pm UTC](https://discuss.elastic.co/t/use-part-of-the-log-files-name-for-the-index/246366/4 "2020-09-23T14:04:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
