# exception=\>#\<CSV::MalformedCSVError: Illegal quoting in line 1.\>

**URL:** <https://discuss.elastic.co/t/exception-csv-illegal-quoting-in-line-1/291437>\
**Category:** Logstash\
**Created:** [December 10, 2021, 3:05pm UTC](https://discuss.elastic.co/t/exception-csv-illegal-quoting-in-line-1/291437 "2021-12-10T15:05:21Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![stillfreem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stillfreem/32/85628_2.png) [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Post date:** [December 10, 2021, 3:05pm UTC](https://discuss.elastic.co/t/exception-csv-illegal-quoting-in-line-1/291437/1 "2021-12-10T15:05:21Z")

</div>

My config file is:

```auto
	{
	stdin{}
	}

filter
{
if "box_Firewall" not in [program] {

        if [message] =~ /{".*":\s".*",/ {
                                        json { source => "message" }
                                        mutate { add_tag => "json" }                                  
                                 }
        else if [message] =~ /\w+=\w+\s\w+=\w+/ {
                                        kv { source => "message" }
                                        mutate { add_tag => "kv" }
             }
        else {
                csv {
                        source => "message"
                        separator => " "
                    }
                mutate { add_tag => "csv" }
             }
}
else { drop{} }
}

output
{
             stdout{}
}

```

my entry is:  
`[ActiveJob] [StorageClusterReplicaVerifierJob] [6f622ec3-0e49-4aba-a5bd-2df8bb83b1aa] Enqueued StorageReplicationVerificationJob (Job ID: aa4386d8-6dac-410d-a954-5f434f749aa2) to Aqueduct(storage_cluster) with arguments: {"oid"=>"73e53d8ceab9a9bf1c395c355dbf60ebf107c438361ca80ff41894f72262b3d3", "hosts"=>["storage-server-6b256858-8802-11eb-85e1-000d3a249d7a", "storage-server-a19d055e-8757-11eb-af0e-000d3aae22c6"]}`

When I paste it on the terminal the following error pops up

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/f/4/f4164c1d204e20e6f09963ae6b7af6c5e5206439.png)

The filter part is because I'm expecting several types of logs = key=value, value only and json  
Any help would be much appreciated 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 10, 2021, 4:59pm UTC](https://discuss.elastic.co/t/exception-csv-illegal-quoting-in-line-1/291437/2 "2021-12-10T16:59:34Z")

</div>

> [@stillfreem](#):
>
> Any help would be much appreciated

You data does not match either regexp. It is not words separated by colons, and it is not words separated by equals signs, so it goes through the csv filter. csv fields have to be quoted correctly. The field must start and end with " (if quotes are present at all) and any quotes within the field must be escaped with a second double quote. So something like `foo,"a""b""c",bar` would be a valid 3 field csv.

You need another branch to your if-else and another filter to parse that data.

---

<div class="post-metadata">

**Author:** ![stillfreem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stillfreem/32/85628_2.png) [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Post date:** [December 13, 2021, 4:06pm UTC](https://discuss.elastic.co/t/exception-csv-illegal-quoting-in-line-1/291437/3 "2021-12-13T16:06:49Z")

</div>

Awesome @Badger I used dissect and it worked 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 10, 2022, 4:07pm UTC](https://discuss.elastic.co/t/exception-csv-illegal-quoting-in-line-1/291437/4 "2022-01-10T16:07:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
