# Csv: map each field name to an array index

**URL:** <https://discuss.elastic.co/t/csv-map-each-field-name-to-an-array-index/316673>\
**Category:** Logstash\
**Created:** [October 15, 2022, 7:47am UTC](https://discuss.elastic.co/t/csv-map-each-field-name-to-an-array-index/316673 "2022-10-15T07:47:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ktomu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ktomu/32/3975_2.png) [@ktomu](https://discuss.elastic.co/u/ktomu)\
**Post date:** [October 15, 2022, 7:47am UTC](https://discuss.elastic.co/t/csv-map-each-field-name-to-an-array-index/316673/1 "2022-10-15T07:47:49Z")

</div>

Hi, I have a csv file with 2000 fields and I need only 5 from them and I know their position. It's easy to get that 5 fields using filebeat (decode\_csv\_fields and extract\_array) because everything that I need it just map each field name to an array index.  
But how can I do the same in logstash? It looks like in logstash you need specify all fields before be able to access to them. For me it is overkill because I need only 5 from 2k

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [October 15, 2022, 3:59pm UTC](https://discuss.elastic.co/t/csv-map-each-field-name-to-an-array-index/316673/2 "2022-10-15T15:59:03Z")

</div>

You may be able to achieve what you want doing a little trick with the [split](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-split) action of the `mutate` filter.

You will not use the `csv` filter to parse it, but use the mutate split to transform your `message` field into an array, then you will add the files based on the array index.

Something like this:

```auto
filter {
    mutate {
        split => { "message" => "," }
    }
    mutate {
        add_field => {
            "field_1" => "%{[message][0]}"
            "field_2" => "%{[message][1]}"
            "field_N" => "%{[message][N]}"
        }
    }
}

```

This may not work correctly if you have values with `,` in it in your CSV.

---

<div class="post-metadata">

**Author:** ![ktomu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ktomu/32/3975_2.png) [@ktomu](https://discuss.elastic.co/u/ktomu)\
**Post date:** [October 15, 2022, 6:06pm UTC](https://discuss.elastic.co/t/csv-map-each-field-name-to-an-array-index/316673/3 "2022-10-15T18:06:22Z")

</div>

It's working!!! Thanks a lot!

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 15, 2022, 8:41pm UTC](https://discuss.elastic.co/t/csv-map-each-field-name-to-an-array-index/316673/4 "2022-10-15T20:41:21Z")

</div>

You can also use prune plugin for whitelist names.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 12, 2022, 8:41pm UTC](https://discuss.elastic.co/t/csv-map-each-field-name-to-an-array-index/316673/5 "2022-11-12T20:41:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
