# Header issue in logstash csv output

**URL:** <https://discuss.elastic.co/t/header-issue-in-logstash-csv-output/175781>\
**Category:** Logstash\
**Created:** [April 8, 2019, 7:59am UTC](https://discuss.elastic.co/t/header-issue-in-logstash-csv-output/175781 "2019-04-08T07:59:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![sahere37](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Post date:** [April 8, 2019, 7:59am UTC](https://discuss.elastic.co/t/header-issue-in-logstash-csv-output/175781/1 "2019-04-08T07:59:09Z")

</div>

hi all, i am using following logstash configuration:

```
input {
elasticsearch {
hosts => ["localhost:9200"]
index => "disp_2019-04-08"
}
}

filter {
mutate {
  add_field => {
   "P_date" => "%{PDate}"
   
  }
  }
mutate { gsub => ["PDate", "-", "/"] }

mutate {
	add_field => {
		"Disp_log" => "%{PDate}|%{Date}|%{Time}|%{PacketSerial}"
	}
	}
}
output {
csv {
fields => ["Disp_log"]
path => "E:/logstashlog/disp_logs/disp_%{P_date}.csv"
csv_options => {
        "write_headers" => true
        "headers" =>["PDate|Date|Time|PacketSerial"]
}
}
  stdout { codec => rubydebug }

}

```

but the problem is that, when i started the logstash, in the created csv output, there is a header for every record while it is needed to have just one record for csv output file. how can i handle this issue? could you please advise me? many thanks.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 8, 2019, 10:55am UTC](https://discuss.elastic.co/t/header-issue-in-logstash-csv-output/175781/2 "2019-04-08T10:55:37Z")

</div>

> [@sahere37](#):
>
> in the created csv output, there is a header for every record

I believe that is working as expected. There is an [issue](https://github.com/logstash-plugins/logstash-output-csv/issues/8) open to change that.

---

<div class="post-metadata">

**Author:** ![sahere37](https://avatars.discourse-cdn.com/v4/letter/s/b2d939/32.png) [@sahere37](https://discuss.elastic.co/u/sahere37)\
**Post date:** [April 8, 2019, 1:51pm UTC](https://discuss.elastic.co/t/header-issue-in-logstash-csv-output/175781/3 "2019-04-08T13:51:35Z")

</div>

is there any way to have just one header for all records?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 6, 2019, 1:51pm UTC](https://discuss.elastic.co/t/header-issue-in-logstash-csv-output/175781/4 "2019-05-06T13:51:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
