# Configure logstash to receive different csv files from filebeat and send it to different index

**URL:** <https://discuss.elastic.co/t/configure-logstash-to-receive-different-csv-files-from-filebeat-and-send-it-to-different-index/110224>\
**Category:** Logstash\
**Created:** [December 5, 2017, 12:16am UTC](https://discuss.elastic.co/t/configure-logstash-to-receive-different-csv-files-from-filebeat-and-send-it-to-different-index/110224 "2017-12-05T00:16:35Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ArunPhilip](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@ArunPhilip](https://discuss.elastic.co/u/ArunPhilip)\
**Post date:** [December 5, 2017, 12:16am UTC](https://discuss.elastic.co/t/configure-logstash-to-receive-different-csv-files-from-filebeat-and-send-it-to-different-index/110224/1 "2017-12-05T00:16:35Z")

</div>

i am trying to configure the logstash to receive different csv files (/var/ticket/adr/adr\_20171204101010.csv and /var/ticket/idr/idr\_20171204101012.csv) from another server using filebeat . how to configure the logstash to send these files to different index , currently i am getting all these csv in single index.  
the fields are different. how to define the columns for these different csv files as well .

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 6, 2017, 6:40am UTC](https://discuss.elastic.co/t/configure-logstash-to-receive-different-csv-files-from-filebeat-and-send-it-to-different-index/110224/2 "2017-12-06T06:40:15Z")

</div>

Use a csv filter to parse the CSV data into different fields. Use the `fields` configuration option on the Logstash side to add fields that describe the kind of data in each file. With that in place you can e.g. add conditionals in your Logstash output to choose between different elasticsearch outputs. This is a commonly asked question so there should be plenty of examples in the archives.

---

<div class="post-metadata">

**Author:** ![ArunPhilip](https://avatars.discourse-cdn.com/v4/letter/a/5f8ce5/32.png) [@ArunPhilip](https://discuss.elastic.co/u/ArunPhilip)\
**Post date:** [December 11, 2017, 5:14pm UTC](https://discuss.elastic.co/t/configure-logstash-to-receive-different-csv-files-from-filebeat-and-send-it-to-different-index/110224/3 "2017-12-11T17:14:19Z")

</div>

Thanks for the response. i will try it out.

is there any option to define the first raw as the the column names.

autodetect\_column\_names =\> true

i tried it by enabling the autodetect\_column\_names option but it didnt work out.

it works only if i manually defines it

columns =\> ["userID" , "Date(ms)" , "Type" , "StartDate(ms)" , "Duration(s)"]

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 8, 2018, 5:14pm UTC](https://discuss.elastic.co/t/configure-logstash-to-receive-different-csv-files-from-filebeat-and-send-it-to-different-index/110224/4 "2018-01-08T17:14:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
