# Error parsing csv field message

**URL:** <https://discuss.elastic.co/t/error-parsing-csv-field-message/171360>\
**Category:** Logstash\
**Created:** [March 7, 2019, 5:22pm UTC](https://discuss.elastic.co/t/error-parsing-csv-field-message/171360 "2019-03-07T17:22:59Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![drivera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drivera/32/39900_2.png) [@drivera](https://discuss.elastic.co/u/drivera)\
**Post date:** [March 7, 2019, 5:22pm UTC](https://discuss.elastic.co/t/error-parsing-csv-field-message/171360/1 "2019-03-07T17:22:59Z")

</div>

Recently upgraded to LS 5.6.15 and began receiving the error below. Is this a break in this version of LS? Do you see anything wrong with my config? Thanks.

Error message:  
[logstash.filters.csv] Error parsing csv {:field=\>"message"

Config file:

```
           if [message] =~ /^".*"/ {
                csv {
                    columns => ["attack_type","timestamp","dest_ip","dest_port","device_id","geo_location",
                                "http_class_name","ip_address_intelligence","ip_client","ip_with_route_domain",
                                "is_truncated","management_ip_address","Method","policy_apply_date","policy_name",
                                "Protocol","query_string","Request","request_status","response_code",
                                "route_domain","session_id","Severity","sig_ids","sig_names","sig_set_names",
                                "src_port","sub_violations","support_id","unit_hostname","Uri","Username",
                                "violation_details","violation_rating","Violations","virus_name","websocket_direction",
                                "websocket_message_type","x_forwarded_for_header_value","Response"]
                    add_tag => ["waf", "asm"]
                    remove_field => ["message"]
                    # convert => { "dest_port" => "integer", "response_code" => "integer", "src_port" => "integer" }
                }
                grok {
                    #match => ["timestamp", 'ASM:"%{timestamp}"']
                    # remove_field => ["message"]
                    remove_tag => ['_grokparsefailure']
                }
            }
            else
            {
                mutate {
                    add_tag => ["malformed"]
                }
            }

    }
    else {
        grok {
            break_on_match => true
            match => [
                "message", "%{SYSLOG5424LINE}",
                "message", "%{SYSLOGLINE}"
            ]
        }
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 7, 2019, 5:49pm UTC](https://discuss.elastic.co/t/error-parsing-csv-field-message/171360/2 "2019-03-07T17:49:28Z")

</div>

> [@drivera](#):
>
> Error message:  
> [logstash.filters.csv] Error parsing csv {:field=\>"message"

What is the complete error message?

---

<div class="post-metadata">

**Author:** ![drivera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drivera/32/39900_2.png) [@drivera](https://discuss.elastic.co/u/drivera)\
**Post date:** [March 7, 2019, 7:02pm UTC](https://discuss.elastic.co/t/error-parsing-csv-field-message/171360/3 "2019-03-07T19:02:06Z")

</div>

Here you go Badger:  
indent preformatted text by 4 spaces  
[2019-03-07T10:48:15,976][WARN][logstash.filters.csv] Error parsing csv {:field=\>"message", :source=\>"\<134\>Mar 7 10:48:14 10.84.0.59 [hostname.esri.com](http://hostname.esri.com) ASM:"","2019-03-07 10:48:14","10.36.129.8","80","N/A","US","/ASG/esri\_ColdFusion\_WebHelp\_PRD\_http.app/esri\_ColdFusion\_WebHelp\_PRD\_http\_vs","N/A","64.62.252.174","64.62.252.174%0","","10.249.212.138","GET","2018-09-07 10:31:15","/ASG/esri\_ColdFusion\_WebHelp\_PRD\_http.app/esri\_ColdFusion\_WebHelp\_PRD\_http\_vs","HTTP","itemID=6779","GET /arcgisdesktop/9.3/toc.cfm?itemID=6779 HTTP/1.1\nFrom: [the.knowledge.ai@gmail.com](mailto:the.knowledge.ai@gmail.com)\nHost: [webhelp.xxxx.com](http://webhelp.xxxx.com)\nConnection: Keep-Alive\nUser-Agent: The Knowledge AI\nAccept-Encoding: gzip,deflate\nX-Forwarded-For: 64.62.252.174\n\n","passed","200","0","28ed72ecb67bc5a1","Informational","","","","59804","","17802897188554385068","[hostname.xxxx.com](http://hostname.xxxx.com)","/arcgisdesktop/9.3/toc.cfm","N/A","","0","","N/A","N/A","N/A","64.62.252.174","Only illegal requests are logged"", :exception=\>#\<CSV::MalformedCSVError: Illegal quoting in line 1.\>}  
[2019-03-07T10:48:15,977][WARN][logstash.filters.csv] Error parsing csv {:field=\>"message", :source=\>"\<134\>Mar 7 10:48:14 10.84.0.59 [hostname.xxxx.com](http://hostname.xxxx.com) ASM:"","2019-03-07 10:48:14","10.36.129.8","80","N/A","US","/ASG/xxxx\_ColdFusion\_WebHelp\_PRD\_http.app/xxxxx\_ColdFusion\_WebHelp\_PRD\_http\_vs","N/A","64.62.252.174","64.62.252.174%0","","10.249.212.138","GET","2018-09-07 10:31:15","/ASG/esri\_ColdFusion\_WebHelp\_PRD\_http.app/esri\_ColdFusion\_WebHelp\_PRD\_http\_vs","HTTP","ID=6779&TopicName=Address%20Locator%20Properties%20dialog%20box","GET /arcgisdesktop/9.3/head.cfm?ID=6779&TopicName=Address%20Locator%20Properties%20dialog%20box HTTP/1.1\nFrom: [the.knowledge.ai@gmail.com](mailto:the.knowledge.ai@gmail.com)\nHost: [webhelp.esri.com](http://webhelp.esri.com)\nConnection: Keep-Alive\nUser-Agent: The Knowledge AI\nAccept-Encoding: gzip,deflate\nX-Forwarded-For: 64.62.252.174\n\n","passed","200","0","9ab2e74dd3b0cc68","Informational","","","","59804","","17802897188554385060","[hostname.esri.com](http://hostname.esri.com)","/arcgisdesktop/9.3/head.cfm","N/A","\<?xml version='1.0' encoding='UTF-8'?\>\<BAD\_MSG\>\<violation\_masks\>0000000000000000-00000000000000005cf7d3eb6b0c2fdb-40000000000000005cf7d3eb6b0c2fdb-40000000000000000000008000000000-0000000000000000\</violation\_masks\>\<viol\_index\>24\</viol\_index\>\<viol\_name\>VIOL\_PARAMETER\_VALUE\_METACHAR\</viol\_name\>\<parameter\_data\>\<value\_error/\>\<enforcement\_level\>global\</enforcement\_level\>VG9waWNOYW1lQWRkcmVzcyBMb2NhdG9yIFByb3BlcnRpZXMgZGlhbG9nIGJveA==\</parameter\_data\>\<wildcard\_entity\>\*\</wildcard\_entity\>1\<language\_type\>4\</language\_type\>\<metachar\_index\>32\</metachar\_index\>\</BAD\_MSG\>","1","","N/A","N/A","N/A","64.62.252.174","Only illegal requests are logged"", :exception=\>#\<CSV::MalformedCSVError: Illegal quoting in line 1.\>}  
indent preformatted text by 4 spaces

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 7, 2019, 7:58pm UTC](https://discuss.elastic.co/t/error-parsing-csv-field-message/171360/4 "2019-03-07T19:58:34Z")

</div>

> [@drivera](#):
>
> [2019-03-07T10:48:15,976][WARN][logstash.filters.csv] Error parsing csv {:field=\>"message", :source=\>"\<134\>Mar 7 10:48:14 10.84.0.59 [hostname.esri.com](http://hostname.esri.com) ASM:"","2019-03-07 10:48:14","10.36.129.8"

So the first column of the CSV is

```
<134>Mar 7 10:48:14 10.84.0.59 [hostname.esri.com](http://hostname.esri.com) ASM:""

```

That's what is causing the CSV::MalformedCSVError: Illegal quoting. Each column should start and end with " if it is quoted. You cannot start quoting a field part way through. I suggest something like

```
dissect { mapping => { "message" => "%{syslogHeader} ASM:%{csvData}" } }

```

---

<div class="post-metadata">

**Author:** ![drivera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/drivera/32/39900_2.png) [@drivera](https://discuss.elastic.co/u/drivera)\
**Post date:** [March 7, 2019, 9:01pm UTC](https://discuss.elastic.co/t/error-parsing-csv-field-message/171360/5 "2019-03-07T21:01:33Z")

</div>

Thanks Badger, I see that you are recommending using dissect. How could I fix it for now using the CSV filter?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 7, 2019, 9:06pm UTC](https://discuss.elastic.co/t/error-parsing-csv-field-message/171360/6 "2019-03-07T21:06:41Z")

</div>

Are you telling me that

```
<134>Mar 7 10:48:14 10.84.0.59 hostname.esri.com ASM:""

```

is the attack type? Surely you need to remove that. I was suggesting that you do that using dissect and then feed the csvData field to your existing csv filter.

If that really is the attack type then you can remove the double quotes using

```
mutate { gsub => ["message" ' ASM:"",', " ASM:,"] }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2019, 9:06pm UTC](https://discuss.elastic.co/t/error-parsing-csv-field-message/171360/7 "2019-04-04T21:06:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
