# ES Ingest

**URL:** https://discuss.elastic.co/t/es-ingest/170186
**Category:** Elasticsearch
**Created:** [February 27, 2019, 2:56pm UTC](https://discuss.elastic.co/t/es-ingest/170186 "2019-02-27T14:56:48Z")
**Posts on this page:** 5
**Page:** 1

<div class="post-metadata">

### Author: ![jogoinar10](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jogoinar10/32/20068_2.png) [@jogoinar10](https://discuss.elastic.co/u/jogoinar10)
#### Post date: [February 27, 2019, 2:56pm UTC](https://discuss.elastic.co/t/es-ingest/170186/1 "2019-02-27T14:56:48Z")

</div>

I want to ingest csv data but the string data output a double quotation.

Below is an example of my data:  
`2019-02-14 16:10:19,"Mike","Foster","M","24"`

Here's the pipeline

```
PUT _ingest/pipeline/sample
{
"description" : "Sample Pipeline",
"processors" : [
		{
			"grok" : {
				"field" : "message",
				"patterns" : ["%{DATA:logtime},%{DATA:first_name},%{DATA:last_name},%{DATA:age}"]
			}
		}
		]
}

```

and Here is the output:

```
"_source": {
                    "logtime": "\"2019-02-27T12:32:33.768Z\"",
                    "first_name": "\"Mike\"",
                    "last_name": "\"Foster\"",
                    "age": "\"24\""
}

```

I want to git rid of the double quote.

TIA

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [February 27, 2019, 5:38pm UTC](https://discuss.elastic.co/t/es-ingest/170186/2 "2019-02-27T17:38:11Z")

</div>

May be run with `\"` in your grok filter.

Better to use btw the dissect processor. Should be faster: [https://www.elastic.co/guide/en/elasticsearch/reference/current/dissect-processor.html](https://www.elastic.co/guide/en/elasticsearch/reference/current/dissect-processor.html)

Also have a look at the CSV processor : [https://github.com/johtani/elasticsearch-ingest-csv](https://github.com/johtani/elasticsearch-ingest-csv)

---

<div class="post-metadata">

### Author: ![jogoinar10](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jogoinar10/32/20068_2.png) [@jogoinar10](https://discuss.elastic.co/u/jogoinar10)
#### Post date: [March 4, 2019, 3:22am UTC](https://discuss.elastic.co/t/es-ingest/170186/3 "2019-03-04T03:22:38Z")

</div>

Thanks for the input @dadoonet.

I already tried the `\"` but I encountered an error.

I'll try the other 2. thanks

---

<div class="post-metadata">

### Author: ![dadoonet](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dadoonet/32/137187_2.png) [@dadoonet](https://discuss.elastic.co/u/dadoonet)
#### Post date: [March 4, 2019, 10:46am UTC](https://discuss.elastic.co/t/es-ingest/170186/4 "2019-03-04T10:46:02Z")

</div>

> [@jogoinar10](#):
>
> I already tried the `\"` but I encountered an error.

Could you share what you did?  
A full `_simulate` example would be helpful to help you.

See for example: [Ingest pipline - multiple fields processed by one porcessor - #7 by dadoonet](https://discuss.elastic.co/t/ingest-pipline-multiple-fields-processed-by-one-porcessor/170320/7)

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [April 1, 2019, 10:56am UTC](https://discuss.elastic.co/t/es-ingest/170186/5 "2019-04-01T10:56:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
