# How do I conditionally parse a CSV into different columns?

**URL:** <https://discuss.elastic.co/t/how-do-i-conditionally-parse-a-csv-into-different-columns/278884>\
**Category:** Logstash\
**Created:** [July 16, 2021, 10:47am UTC](https://discuss.elastic.co/t/how-do-i-conditionally-parse-a-csv-into-different-columns/278884 "2021-07-16T10:47:58Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![nsouth](https://avatars.discourse-cdn.com/v4/letter/n/ecccb3/32.png) [@nsouth](https://discuss.elastic.co/u/nsouth)\
**Post date:** [July 16, 2021, 10:47am UTC](https://discuss.elastic.co/t/how-do-i-conditionally-parse-a-csv-into-different-columns/278884/1 "2021-07-16T10:47:58Z")

</div>

I have CSV log files where the columns change from line to line. The first field is an `eventCode`, which I can use to know which subsequent columns to expect. Here's a representative example.

```auto
1,sameTaskId,username,size
2,sameTaskId,networkstats
1,anotherTaskId,username,size
3,sameTaskId,authAuditInfo
2,anotherTaskId,networkstats
3,anotherTaskId,authAuditInfo

```

(I also need to aggregate based on a `TaskId`, but that's another topic.)

**How do I conditionally parse a line into the desired columns?** I'm new to Logstash and to Ruby, so I'm stumbling a lot. With the below, I get an error `Ruby exception occurred: undefined method '[]' for #<LogStash::Event:0x2bb54c8c>` , which I guess is because I'm trying to get the first column value the wrong way.

```auto
ruby {
    code => "@metadata['eventCode'] = event['message'][0..event['message'].index(',')]"
}

if [@metadata][eventCode] == 1 {
    csv {
	    skip_header => true
        columns => ["myColA", "myColB"]
	}
} else if [@metadata][eventCode] == 2 {
    csv {
	    skip_header => true
        columns => ["myColA", "myColC"]
    }
}

```

Thanks!

---

<div class="post-metadata">

**Author:** ![nsouth](https://avatars.discourse-cdn.com/v4/letter/n/ecccb3/32.png) [@nsouth](https://discuss.elastic.co/u/nsouth)\
**Post date:** [July 16, 2021, 7:57pm UTC](https://discuss.elastic.co/t/how-do-i-conditionally-parse-a-csv-into-different-columns/278884/2 "2021-07-16T19:57:58Z")

</div>

I got something working using regular expressions! See below.

```auto
  if ([message] =~ /^1,/ ) {  
    csv {
	    skip_header => true
        columns => ["myColA", "myColB"]
	}
    }
  } else if ([message] =~ /^2,/ ) {   
       csv {
	    skip_header => true
        columns => ["myColA", "myColC"]
    }
  } else { drop {}}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 13, 2021, 7:58pm UTC](https://discuss.elastic.co/t/how-do-i-conditionally-parse-a-csv-into-different-columns/278884/3 "2021-08-13T19:58:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
