# \_csvparsing failure in logstash with delimeters

**URL:** https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499
**Category:** Logstash
**Created:** [February 5, 2024, 3:36am UTC](https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499 "2024-02-05T03:36:19Z")
**Posts on this page:** 7
**Page:** 1

<div class="post-metadata">

### Author: ![shailendra1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shailendra1/32/122783_2.png) [@shailendra1](https://discuss.elastic.co/u/shailendra1)
#### Post date: [February 5, 2024, 3:36am UTC](https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499/1 "2024-02-05T03:36:19Z")

</div>

Hi all,  
i am testing a logstash pipelines with the csv data which have approx 20 headers but i am trying with the 3 fields and csv delimeter tab is giving me parsing failures . i also tried with the quote\_char but it is the same .  
sample data events

```auto
(PDH-CSV 4.0) (Malay Peninsula Standard Time)(-480)	\\W01BUAMSDB3A\Processor Information(_Total)\% Processor Time	\\W01BUAMSDB3A\Memory\Available MBytes
01/31/2024 10:30:43.065	26.37411962	30405
01/31/2024 10:31:43.057	6.410672288	30360

```

this is my logstash configurations

```auto
filter {
        csv {
                separator => "\t"
                columns => ["timestamp", "processor_time", "available_memory"]
                skip_empty_columns => "true"
                quote_char => " \\ "
        }
        ### Date conversion ####
        date {
                match => ["timestamp", "MM/dd/yyyy HH:mm:ss.SSS"]
                target => "@timestamp_log"
                }
        date {
                match => ["timestamp", "YYYY-MM-DD'T'HH:mm:ss.SSSSSSSSS'Z'"]
                target => "@timestamp_raw"
        }
}
output
{
        stdout { codec => rubydebug }

```

i am getting the \_csvparsing failures. pl suggest if any other options can be used to parse these colums.

```auto
      "event" => {
        "original" => "(PDH-CSV 4.0) (Malay Peninsula Standard Time)(-480)\t\\\\W01BUAMSDB3A\\Processor Information(_Total)\\% Processor Time\t\\\\W01BUAMSDB3A\\Memory\\Available MBytes"
    },
    "@timestamp" => 2024-02-05T03:30:33.874316203Z,
          "tags" => [
        [0] "_csvparsefailure"
    ],

```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [February 5, 2024, 3:55am UTC](https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499/2 "2024-02-05T03:55:29Z")

</div>

> [@shailendra1](#):
>
> ```auto
> csv {
> separator => "\t"
> 
> ```

According to the documentation you need a [literal tab](https://www.elastic.co/guide/en/logstash/current/plugins-filters-csv.html#plugins-filters-csv-separator) there, not \t.

---

<div class="post-metadata">

### Author: ![shailendra1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shailendra1/32/122783_2.png) [@shailendra1](https://discuss.elastic.co/u/shailendra1)
#### Post date: [February 5, 2024, 4:23am UTC](https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499/3 "2024-02-05T04:23:04Z")

</div>

sorry @Badger , i did not understand what is means by literal tab .  
is it refereing to '\t' ?  
i tried with it and its reporting the same response.  
\_csvparsefailures.

i tried with the "\tab" but its also same reporting.

```auto
"message" => "(PDH-CSV 4.0) (Malay Peninsula Standard Time)(-480)\t\\\\W01BUAMSDB3A\\Processor Information(_Total)\\% Processor Time\t\\\\W01BUAMSDB3A\\Memory\\Available MBytes",
          "host" => {
        "name" => "v097a.uat.abcd.com"
    },
          "tags" => [
        [0] "_csvparsefailure"

```

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [February 5, 2024, 4:53am UTC](https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499/4 "2024-02-05T04:53:56Z")

</div>

> [@shailendra1](#):
>
> i did not understand what is means by literal tab

You cannot use \t, you cannot use \tab, you need to use the ASCII tab character, which is 0x09.

On my system I would have to reconfigure my editor not to replace tabs with spaces before trying to type a tab in a file.

---

<div class="post-metadata">

### Author: ![shailendra1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shailendra1/32/122783_2.png) [@shailendra1](https://discuss.elastic.co/u/shailendra1)
#### Post date: [February 6, 2024, 3:17am UTC](https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499/5 "2024-02-06T03:17:27Z")

</div>

i am in unix machine, and i tried with this format but i am getting this output even i tried to pass with one column in csv formats.

```auto
      "message" => "(PDH-CSV 4.0) (Malay Peninsula Standard Time)(-480)\t\\\\W01BUABCDF8B\\Processor
    "@timestamp" => 2024-02-06T02:40:00.603411786Z,
          "host" => {
        "name" => "x977a.vsi.abcd.com"
    },
     "timestamp" => "(PDH-CSV 4.0) (Malay Peninsula Standard Time)(-480)\t\\\\W01BUABCDF8B\\Processor
}

```

Below is my logstash configurations filter

```auto
filter {
 22 csv {
 23 separator => ","
 24 columns => ["timestamp", "processor_time"]
 25 skip_empty_columns => "true"
 26 #quote_char => ' \\" '
 27 }

```

may you suggest any other methods to parse these fileds ,

---

<div class="post-metadata">

### Author: ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)
#### Post date: [February 6, 2024, 2:51pm UTC](https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499/6 "2024-02-06T14:51:57Z")

</div>

WIth this configuration

```
input { generator { count => 1 lines => ['(PDH-CSV 4.0) (Malay Peninsula Standard Time)(-480) \\W01BUABCDF8B\Processor'] } }

output { stdout { codec => rubydebug { metadata => false } } }
filter {
    csv { separator => " " columns => ["timestamp", "processor_time"] skip_empty_columns => "true" }
}

```

I get

```
     "timestamp" => "(PDH-CSV 4.0) (Malay Peninsula Standard Time)(-480)",
"processor_time" => "\\\\W01BUABCDF8B\\Processor",
       "message" => "(PDH-CSV 4.0) (Malay Peninsula Standard Time)(-480)\t\\\\W01BUABCDF8B\\Processor"

```

That is with a tab character in the message and in the separator option.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 5, 2024, 2:52pm UTC](https://discuss.elastic.co/t/csvparsing-failure-in-logstash-with-delimeters/352499/7 "2024-03-05T14:52:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
