# Can we use " :: " as a separator in csv filter in logstash

**URL:** <https://discuss.elastic.co/t/can-we-use-as-a-separator-in-csv-filter-in-logstash/246983>\
**Category:** Logstash\
**Created:** [August 31, 2020, 4:34pm UTC](https://discuss.elastic.co/t/can-we-use-as-a-separator-in-csv-filter-in-logstash/246983 "2020-08-31T16:34:31Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Shahid\_Mustafa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahid_mustafa/32/46287_2.png) [@Shahid\_Mustafa](https://discuss.elastic.co/u/Shahid_Mustafa)\
**Post date:** [August 31, 2020, 4:34pm UTC](https://discuss.elastic.co/t/can-we-use-as-a-separator-in-csv-filter-in-logstash/246983/1 "2020-08-31T16:34:32Z")

</div>

Can we use following csv filter:  
I cannot test this directly in our system.

```auto
csv {
                                  columns => ["LogLevel", "DateTime", "RequestID", "LogMessage"]
                                    separator => " :: "
                                    skip_header => "false"
                                }

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [August 31, 2020, 4:47pm UTC](https://discuss.elastic.co/t/can-we-use-as-a-separator-in-csv-filter-in-logstash/246983/2 "2020-08-31T16:47:46Z")

</div>

Tested with 7.9

```auto
input {
  generator {
    lines => [
     'LogLevel :: DateTime :: RequestID :: LogMessage'
    ]
    count => 1
    codec => "line"
  }
}
filter {
    csv {
        columns => ["LogLevel", "DateTime", "RequestID", "LogMessage"]
        separator => " :: "
        skip_header => "false"
    }
}
output {
  stdout { codec => "rubydebug" }
}

```

Output

```auto
{
      "DateTime" => "DateTime",
     "RequestID" => "RequestID",
      "@version" => "1",
    "@timestamp" => 2020-08-31T16:46:36.698Z,
          "host" => "MacBook-Pro.domain",
      "LogLevel" => "LogLevel",
       "message" => "LogLevel :: DateTime :: RequestID :: LogMessage",
    "LogMessage" => "LogMessage"
}

```

So the answer is yes.

---

<div class="post-metadata">

**Author:** ![Shahid\_Mustafa](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shahid_mustafa/32/46287_2.png) [@Shahid\_Mustafa](https://discuss.elastic.co/u/Shahid_Mustafa)\
**Post date:** [September 1, 2020, 5:57am UTC](https://discuss.elastic.co/t/can-we-use-as-a-separator-in-csv-filter-in-logstash/246983/3 "2020-09-01T05:57:34Z")

</div>

Thanks. You are awesome. Just one last thing - I guess I will have to install logstash on my machine to test this. How do I test this after installing logstash - what commands, configuration?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [September 1, 2020, 11:59am UTC](https://discuss.elastic.co/t/can-we-use-as-a-separator-in-csv-filter-in-logstash/246983/4 "2020-09-01T11:59:13Z")

</div>

Get the [download](https://www.elastic.co/downloads/logstash) and follow the steps.

The `-f filename.conf` is the only part you need to change. Which is the path to the .conf file you create.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2020, 11:59am UTC](https://discuss.elastic.co/t/can-we-use-as-a-separator-in-csv-filter-in-logstash/246983/5 "2020-09-29T11:59:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
