# CSV filter not working properly

**URL:** <https://discuss.elastic.co/t/csv-filter-not-working-properly/298274>\
**Category:** Logstash\
**Created:** [February 25, 2022, 11:31am UTC](https://discuss.elastic.co/t/csv-filter-not-working-properly/298274 "2022-02-25T11:31:04Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticity2](https://avatars.discourse-cdn.com/v4/letter/e/c89c15/32.png) [@elasticity2](https://discuss.elastic.co/u/elasticity2)\
**Post date:** [February 25, 2022, 11:31am UTC](https://discuss.elastic.co/t/csv-filter-not-working-properly/298274/1 "2022-02-25T11:31:04Z")

</div>

Hi all, I have a folder which contains two different types of CSV files. My logstash config is as below. When I run logstash, it just ingests the csvs as is without the columns getting generated. If I explicitly mention the file, then it works. I reckon the problem is in the if condition as it doesn't match. Really appreciate if someone could point the issue here. Thank you!

```auto
input {
  file {
    path => "/opt/out/Vol/*.csv"
    start_position => "beginning"
    sincedb_path => "/dev/null"
  }
}
filter {
if [path] =~ "/opt/out/Vol/*pslist.PsList.csv"
{
  csv {
      separator => ","
      skip_header => "true"
      columns => ["TreeDepth","PID","PPID","ImageFileName","Offset(V)","Threads","Handles","SessionId","Wow64","CreateTime","ExitTime","File output"]
  }
  }
else if [path] =~ "/opt/out/Vol/*cmdline.CmdLine.csv"
{
  csv {
      separator => ","
      skip_header => "true"
      columns => ["TreeDepth","PID","Process","Args"]
  }
}

}
output {
   elasticsearch {
     hosts => "http://localhost:9200"
     index => "vol"
  }

stdout {}

}

```

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [February 25, 2022, 12:48pm UTC](https://discuss.elastic.co/t/csv-filter-not-working-properly/298274/2 "2022-02-25T12:48:52Z")

</div>

I'd try something like this.

```auto
  if "pslist" in [path] {
    # CSV Filter
  }
  else if "cmdline" in [path] {
    # CSV Filter
  }   

```

or if it's just 2 different CSV types then make 2 different inputs and then tag them so you know which is which. Then you can use `type` for conditional statements.

```auto
input {
  file {
    path => "/opt/out/Vol/path-to-get-first-type"
    start_position => "beginning"
    sincedb_path => "/dev/null"
    type => "first"
  }
  file {
    path => "/opt/out/Vol/path-to-get-second-type"
    start_position => "beginning"
    sincedb_path => "/dev/null"
    type => "second"
  }
}
filter {
  if [type] == "first" {
    # CSV Filter
  }
  else if [type] == "second" {
    # CSV Filter
  }   
}

```

---

<div class="post-metadata">

**Author:** ![elasticity2](https://avatars.discourse-cdn.com/v4/letter/e/c89c15/32.png) [@elasticity2](https://discuss.elastic.co/u/elasticity2)\
**Post date:** [February 25, 2022, 11:33pm UTC](https://discuss.elastic.co/t/csv-filter-not-working-properly/298274/3 "2022-02-25T23:33:37Z")

</div>

@aaron-nimocks - Thanks a lot. The first solution worked like a charm! I was trying all sorts of things to fix this but none worked.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2022, 11:34pm UTC](https://discuss.elastic.co/t/csv-filter-not-working-properly/298274/4 "2022-03-25T23:34:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
