# Filestream processing of CSV files

**URL:** https://discuss.elastic.co/t/filestream-processing-of-csv-files/326704
**Category:** Elasticsearch
**Tags:** fleet
**Created:** [February 28, 2023, 6:50pm UTC](https://discuss.elastic.co/t/filestream-processing-of-csv-files/326704 "2023-02-28T18:50:48Z")
**Posts on this page:** 4
**Page:** 1

<div class="post-metadata">

### Author: ![rsaeks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsaeks/32/5068_2.png) [@rsaeks](https://discuss.elastic.co/u/rsaeks)
#### Post date: [February 28, 2023, 6:50pm UTC](https://discuss.elastic.co/t/filestream-processing-of-csv-files/326704/1 "2023-02-28T18:50:48Z")

</div>

Hi all,

I'm slowly migrating over to filestream to process some log files and have data coming in and stored into the message field. Here is an example:

ec26.515d.ebcf,someUser,GSS-A-1FL-122,SD35

What I would like to do now is process that data and put it into different fields separated by the comma. Ideally, it would go into the following fields:

macAddress, User, AP, SSID

I think this would be handled by a processor but haven't had any luck with I've put together so far with this:

- decode\_csv\_fields:  
fields:  
message: connectionData

This moves the data into a field called connectionData as an array of the values. If I want to break the values in the message field into new fields separated by the comma is there a different format to the processor I should be using?

Thanks for your help!

---

<div class="post-metadata">

### Author: ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)
#### Post date: [February 28, 2023, 7:10pm UTC](https://discuss.elastic.co/t/filestream-processing-of-csv-files/326704/2 "2023-02-28T19:10:43Z")

</div>

Hi @rsaeks

Writing to separate fields is not how the `decode_csv_fields` processor works

> The `decode_csv_fields` processor decodes fields containing records in comma-separated format (CSV). It will output the values as an array of strings. This processor is available for Filebeat.

Perhaps [dissect](https://www.elastic.co/guide/en/beats/filebeat/current/dissect.html) will work for what you want, it is also very efficient.

---

<div class="post-metadata">

### Author: ![rsaeks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rsaeks/32/5068_2.png) [@rsaeks](https://discuss.elastic.co/u/rsaeks)
#### Post date: [March 1, 2023, 2:22pm UTC](https://discuss.elastic.co/t/filestream-processing-of-csv-files/326704/3 "2023-03-01T14:22:23Z")

</div>

@stephenb - Thank you for the info about using dissect as a processor! That is a much better approach and a whole lot quicker (plus easy to setup)

I appreciate sharing and will be using that one 🙂

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [March 29, 2023, 2:22pm UTC](https://discuss.elastic.co/t/filestream-processing-of-csv-files/326704/4 "2023-03-29T14:22:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
