# CSV filter plugin and autodetect column names

**URL:** <https://discuss.elastic.co/t/csv-filter-plugin-and-autodetect-column-names/194244>\
**Category:** Logstash\
**Created:** [August 7, 2019, 1:35pm UTC](https://discuss.elastic.co/t/csv-filter-plugin-and-autodetect-column-names/194244 "2019-08-07T13:35:49Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Zedd](https://avatars.discourse-cdn.com/v4/letter/z/3ab097/32.png) [@Zedd](https://discuss.elastic.co/u/Zedd)\
**Post date:** [August 7, 2019, 1:35pm UTC](https://discuss.elastic.co/t/csv-filter-plugin-and-autodetect-column-names/194244/1 "2019-08-07T13:35:49Z")

</div>

Hi,

I'm wondering if there is a way to parse one single CSV log using two distinct logstash conf files assuming each conf file would have a CSV filter plugin with autodetect\_column\_names set to true.

As I understand it, the option to autodetect column names drop the header event after reading it.  
Therefore, I suppose this is why the second conf file never gets this event and I get values as column names.

Is there a way to keep this header event for the second configuration file or am I forced to not use a CSV filter in one of my conf files ?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 7, 2019, 2:50pm UTC](https://discuss.elastic.co/t/csv-filter-plugin-and-autodetect-column-names/194244/2 "2019-08-07T14:50:55Z")

</div>

Why would you want to parse the same CSV line twice? If they are running in the same pipeline then the second configuration file has access to all the fields that the first one parsed.

---

<div class="post-metadata">

**Author:** ![Zedd](https://avatars.discourse-cdn.com/v4/letter/z/3ab097/32.png) [@Zedd](https://discuss.elastic.co/u/Zedd)\
**Post date:** [August 7, 2019, 3:18pm UTC](https://discuss.elastic.co/t/csv-filter-plugin-and-autodetect-column-names/194244/3 "2019-08-07T15:18:17Z")

</div>

You're right thank you.  
I just figured this out.  
I come back to elk after more than a year without using it. It's a bit hard to get back to it.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2019, 3:18pm UTC](https://discuss.elastic.co/t/csv-filter-plugin-and-autodetect-column-names/194244/4 "2019-09-04T15:18:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
