# CSV file into ES through logstash

**URL:** <https://discuss.elastic.co/t/csv-file-into-es-through-logstash/179106>\
**Category:** Logstash\
**Created:** [April 30, 2019, 2:38pm UTC](https://discuss.elastic.co/t/csv-file-into-es-through-logstash/179106 "2019-04-30T14:38:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![userelastic](https://avatars.discourse-cdn.com/v4/letter/u/c4cdca/32.png) [@userelastic](https://discuss.elastic.co/u/userelastic)\
**Post date:** [April 30, 2019, 2:38pm UTC](https://discuss.elastic.co/t/csv-file-into-es-through-logstash/179106/1 "2019-04-30T14:38:00Z")

</div>

Newbie here; I am trying to get a CSV file from a windows server and send it to ES through logstash; I am hoping to get the columns in ES so we can do proper searches; but it seems all the CSV output goes into message field.

# I have installed file beats with follwing config:

filebeat.inputs:

- type: log
  - C:\Scripts\Daily\*.csv  
output.logstash:  
hosts: ["192.168.1.101:5044"]  
===================

# LogStash has following config:

# cat /etc/logstash/conf.d/02-beats-input.conf

input {  
beats {  
port =\> 5044  
}  
}

filter {  
if [beat.name] == "server15" and [prospector.type] == "log" {  
csv {  
separator =\> ","  
columns =\> ["Received","SenderAddress","RecipientAddress","Subject","Status","ToIP","FromIP","Size","MessageId","MessageTraceId"]  
}  
}  
}

# output { elasticsearch { hosts =\> ["[http://192.168.1.102:9200](http://192.168.1.102:9200)"] } }

Can someone please give me some tips how to get the CSV data into separate fields in ES.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 30, 2019, 3:14pm UTC](https://discuss.elastic.co/t/csv-file-into-es-through-logstash/179106/2 "2019-04-30T15:14:07Z")

</div>

> [@userelastic](#):
>
> if [beat.name] == "server15" and [prospector.type] == "log" {

[beat.name] (which refers to a field called beat.name) should be [beat][name] (which refers to the field named name in the [beat] object). The same may be true for [prospector.log]

---

<div class="post-metadata">

**Author:** ![userelastic](https://avatars.discourse-cdn.com/v4/letter/u/c4cdca/32.png) [@userelastic](https://discuss.elastic.co/u/userelastic)\
**Post date:** [April 30, 2019, 5:01pm UTC](https://discuss.elastic.co/t/csv-file-into-es-through-logstash/179106/3 "2019-04-30T17:01:33Z")

</div>

awesome; thanks Badger; its fixed.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 28, 2019, 5:01pm UTC](https://discuss.elastic.co/t/csv-file-into-es-through-logstash/179106/4 "2019-05-28T17:01:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
