# CSV::MalformedCSVError: Unquoted fields do not allow \\r or \\n

**URL:** <https://discuss.elastic.co/t/csv-unquoted-fields-do-not-allow-r-or-n/154292>\
**Category:** Logstash\
**Created:** [October 27, 2018, 3:36pm UTC](https://discuss.elastic.co/t/csv-unquoted-fields-do-not-allow-r-or-n/154292 "2018-10-27T15:36:07Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ffknob](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ffknob/32/37008_2.png) [@ffknob](https://discuss.elastic.co/u/ffknob)\
**Post date:** [October 27, 2018, 3:36pm UTC](https://discuss.elastic.co/t/csv-unquoted-fields-do-not-allow-r-or-n/154292/1 "2018-10-27T15:36:07Z")

</div>

Hello,

I'm getting a _CSV::MalformedCSVError_ exception for events where the (possible) multilined field has line breaks. I think I managed to join all the event's lines in one single event (at least that's what I understand, since the "message" seens complete with all the lines) using the multiline codec, but what I don't understand is why this "Unquoted fields do not allow \t or \n" is triggering, even though the field is quoted.

Thank you in advance for your help.

Pipeline:

```
input {
	file {
	path => "/home/ffknob/Entwicklung/workspace/dados-abertos-elk/data/tcers/decisoes/teste.csv"
    	start_position => "beginning"
		sincedb_path => "/dev/null"
		codec => multiline {
			pattern => "^%{YEAR},"
			negate => true 
			what => "previous"
			auto_flush_interval => 2
		}
	}
}
filter {
	csv {
		skip_header => true
		columns => ["ano_sessao","data_sessao","tipo_sessao","cod_orgao_julgador","nome_orgao_julgador","numero_sessao","nr_processo","cod_tipo_processo","tipo_processo","cod_orgao","nome_orgao","cod_gabinete","nome_gabinete","cod_magistrado","nome_magistrado","extra_pauta","retirado_pauta","solicitacao_vista","decisao","link_video_sessao"]
	}
	if [data_sessao] == "DATA_SESSAO" {
		drop { }
	}
}
output {
	stdout { codec => rubydebug }
}

```

Event output:

`[2018-10-27T12:26:56,714][WARN][logstash.filters.csv] Error parsing csv {:field=>"message", :source=>"2017,01/02/2017,Ordinária,3,Tribunal Pleno,2,83300200130,37,Inspeção Extraordinária,55600,PM DE RIO GRANDE,22,Gabinete do Conselheiro Cezar Miola,35,Cezar Miola,Não,Não,Não,\"- Saneamento do feito, com o objetivo de fixar os exercícios de 2011 a 2015 como limite para a presente Inspeção Extraordinária.\n\",http://www1.tce.rs.gov.br/sessoes/2017/20170201_2_3_83300200130.mp4\r", :exception=>#<CSV::MalformedCSVError: Unquoted fields do not allow \r or \n (line 1).>}`

```
{
       "message" => "2017,01/02/2017,Ordinária,3,Tribunal Pleno,2,83300200130,37,Inspeção Extraordinária,55600,PM DE RIO GRANDE,22,Gabinete do Conselheiro Cezar Miola,35,Cezar Miola,Não,Não,Não,\"- Saneamento do feito, com o objetivo de fixar os exercícios de 2011 a 2015 como limite para a presente Inspeção Extraordinária.\n\",http://www1.tce.rs.gov.br/sessoes/2017/20170201_2_3_83300200130.mp4\r",
    "@timestamp" => 2018-10-27T15:26:56.590Z,
      "@version" => "1",
          "tags" => [
        [0] "multiline",
        [1] "_csvparsefailure"
    ],
          "host" => "0.0.0.0",
}
```

---

<div class="post-metadata">

**Author:** ![ffknob](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ffknob/32/37008_2.png) [@ffknob](https://discuss.elastic.co/u/ffknob)\
**Post date:** [October 27, 2018, 3:47pm UTC](https://discuss.elastic.co/t/csv-unquoted-fields-do-not-allow-r-or-n/154292/2 "2018-10-27T15:47:14Z")

</div>

I managed to pass the exception by removing "\n" before the csv filter takes in, but with this solution I lose all the line breaks inside the text. I guess I could replace "\n" for an exotic character before the csv filter, and then taking it back to "\n" after it breaks the event into fields... But is there any other (and more elegant way) to solve this?

`mutate { gsub => ["message", "\n", ""] }`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2018, 3:53pm UTC](https://discuss.elastic.co/t/csv-unquoted-fields-do-not-allow-r-or-n/154292/3 "2018-11-24T15:53:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
