# Help parsing large CSV files

**URL:** <https://discuss.elastic.co/t/help-parsing-large-csv-files/201974>\
**Category:** Logstash\
**Created:** [October 2, 2019, 2:33pm UTC](https://discuss.elastic.co/t/help-parsing-large-csv-files/201974 "2019-10-02T14:33:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![megajune](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/megajune/32/47012_2.png) [@megajune](https://discuss.elastic.co/u/megajune)\
**Post date:** [October 2, 2019, 2:33pm UTC](https://discuss.elastic.co/t/help-parsing-large-csv-files/201974/1 "2019-10-02T14:33:05Z")

</div>

Hello,

I'm trying to write a logstash plugin for Symantec. JSON isn't an option for this product. Here's an example of the log I'm trying to parse. In actual product, this log will have many more fields.

SymantecServer: Potential risk found,IP Address: 10.2.3.4,Computer name: MyDesktopComputer,Source: Auto-Protect scan,Risk name: WS.Reputation.1,Occurrences: 1

Is there some nice, easy way to pullout fields without using the csv filter? Some usage of the split function on the message itself that results in populated fields? Because the above log is going to have 50+ fields in multiple formats, I'm trying for the past of least resistance here. Any advice you can give I would appreciate. The work I'm currently doing is very likely going to result in a working Symantec Semp logstash plugin that I will share on github.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 2, 2019, 2:37pm UTC](https://discuss.elastic.co/t/help-parsing-large-csv-files/201974/2 "2019-10-02T14:37:37Z")

</div>

Use a kv filter

```
kv { field_split => "," value_split => ":" }
```

---

<div class="post-metadata">

**Author:** ![megajune](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/megajune/32/47012_2.png) [@megajune](https://discuss.elastic.co/u/megajune)\
**Post date:** [October 2, 2019, 5:57pm UTC](https://discuss.elastic.co/t/help-parsing-large-csv-files/201974/3 "2019-10-02T17:57:56Z")

</div>

You nailed it. Thanks.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 30, 2019, 5:57pm UTC](https://discuss.elastic.co/t/help-parsing-large-csv-files/201974/4 "2019-10-30T17:57:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
