# Different field names depending on Record\_Type in CSV file

**URL:** <https://discuss.elastic.co/t/different-field-names-depending-on-record-type-in-csv-file/65907>\
**Category:** Logstash\
**Created:** [November 13, 2016, 1:22pm UTC](https://discuss.elastic.co/t/different-field-names-depending-on-record-type-in-csv-file/65907 "2016-11-13T13:22:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [November 13, 2016, 1:22pm UTC](https://discuss.elastic.co/t/different-field-names-depending-on-record-type-in-csv-file/65907/1 "2016-11-13T13:22:52Z")

</div>

Hi, I have a CSV file with different information depending on the second field value of the CSV file `Record_Type`. Here is an example of the input CSV file:

`08-11-2016 21:08:04,2,4475632030300,655101002121838,25697419 08-11-2016 21:08:05,3, 4475632030300,25697419,*111*222#,39,OND 08-11-2016 21:08:05,8, 4475632030300,25697419,39,http://8.8.40.10:9080/request?ms=44763212345690&sessionid=1&type=1&im=123456789&msg=*119	1	<us><ms> ************</ms><sessionid>******** </sessionid><type>*</type><im> ***************</im><msg>******** #</msg></us> 08-11-2016 21:08:05,9, 4475632030300,25697419,39,http://8.8.40.10:9080/request?ms=4476321234567890&sessionid=1&type=1&im=123456789&msg=*119	1	Welcome0. Please enter`

So the first event returns 2 and has the following fields:  
`08-11-2016 21:08:04,2,4475632030300,655101002121838,25697419`

`Date_Time = 08-11-2016 21:08:04 Record_Type = 2 MS = 4475632030300 IM = 655101002121838 Task_ID = 25697419`

The Second event returns a 3 and has the following fields:  
`08-11-2016 21:08:05,3, 4475632030300,25697419,*111*222#,39,OND`

`Date_Time = 08-11-2016 21:08:05 Record_Type = 3 MS = 4475632030300 Task_ID = 25697419 Code_Nr = *111*222# Men_Nr. = 39 Customer = OND`

The Third event returns an 8 and has the following fields:  
`08-11-2016 21:08:05,8, 4475632030300,25697419,39,http://8.8.40.10:9080/request?ms=44763212345690&sessionid=1&type=1&im=123456789&msg=*119	1	<us><ms> ************</ms><sessionid>******** </sessionid><type>*</type><im> ***************</im><msg>******** #</msg></us>`

`Date_Time = 08-11-2016 21:08:05 Record_Type = 8 MS = 4475632030300 Task_ID = 25697419 Men_Nr. = 39 URL1 = http://8.8.40.10:9080/request?ms=44763212345690&sessionid=1&type=1&im=123456789&msg=*119	1	<us><ms> ************</ms><sessionid>******** </sessionid><type>*</type><im> ***************</im><msg>******** #</msg></us>`

The Fourth event returns an 9 and has the following fields:  
`08-11-2016 21:08:05,9, 4475632030300,25697419,39,http://8.8.40.10:9080/request?ms=4476321234567890&sessionid=1&type=1&im=123456789&msg=*119	1	Welcome0. Please enter`

`Date_Time = 08-11-2016 21:08:05 Record_Type = 9 MS = 4475632030300 Task_ID = 25697419 Men_Nr. = 39 URL2 = http://8.8.40.10:9080/request?ms=4476321234567890&sessionid=1&type=1&im=123456789&msg=*119	1	Welcome0. Please enter`

The `Record_Type` has different number values and according to this value different fields should be assessed under the filter. How can I process a CSV file that contains different Record\_Types with different field structures?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [November 13, 2016, 10:54pm UTC](https://discuss.elastic.co/t/different-field-names-depending-on-record-type-in-csv-file/65907/2 "2016-11-13T22:54:18Z")

</div>

After doing an initial match, you'd need to use conditionals to check the value and then do renames.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2016, 10:54pm UTC](https://discuss.elastic.co/t/different-field-names-depending-on-record-type-in-csv-file/65907/3 "2016-12-11T22:54:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
