# How to add first row first column value as a field in to other rows' documents of a csv file in logstash filters?

**URL:** <https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806>\
**Category:** Logstash\
**Created:** [August 5, 2020, 4:45am UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806 "2020-08-05T04:45:41Z")\
**Posts on this page:** 20\
**Page:** 2

<div class="post-metadata">

**Author:** ![DSMilestone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsmilestone/32/73339_2.png) [@DSMilestone](https://discuss.elastic.co/u/DSMilestone)\
**Post date:** [August 8, 2020, 4:02pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/21 "2020-08-08T16:02:41Z")

</div>

Thanks! But, there will be 100 of reports, will this hash be able to handle that?

```auto
@suite ||= {}
@row ||= {}

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 8, 2020, 4:26pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/22 "2020-08-08T16:26:45Z")

</div>

If it is only hundreds then the memory leak should not matter. If it is more you would have to re-implement things using an aggregate filter. Use the file name as the task id, and save the row number in the map. Set 'push\_map\_as\_event\_on\_timeout =\> true' and in timeout\_code call event.cancel so that map entry gets timed out and deleted but does not show up as an event.

---

<div class="post-metadata">

**Author:** ![DSMilestone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsmilestone/32/73339_2.png) [@DSMilestone](https://discuss.elastic.co/u/DSMilestone)\
**Post date:** [August 8, 2020, 4:30pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/23 "2020-08-08T16:30:17Z")

</div>

Thanks! I'll try that one. 🙂

---

<div class="post-metadata">

**Author:** ![DSMilestone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsmilestone/32/73339_2.png) [@DSMilestone](https://discuss.elastic.co/u/DSMilestone)\
**Post date:** [August 11, 2020, 2:43pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/24 "2020-08-11T14:43:37Z")

</div>

Hi, what does mean of this comment "# Needs a literal newline in the configuration file" in the conf file?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 11, 2020, 2:49pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/25 "2020-08-11T14:49:23Z")

</div>

> [@Badger](#):
>
> ```auto
> mutate { split => { "[@metadata][lines]" => "
> " } } # Needs a literal newline in the configuration file
> 
> ```

That mutate+split is splitting the [@metadata][lines] field into an array, and it needs to split them at each newline character. You cannot use "\n", you have to have a literal newline in the string, so that the filter configuration is split across two lines of the file.

---

<div class="post-metadata">

**Author:** ![DSMilestone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsmilestone/32/73339_2.png) [@DSMilestone](https://discuss.elastic.co/u/DSMilestone)\
**Post date:** [August 11, 2020, 3:18pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/26 "2020-08-11T15:18:47Z")

</div>

ok, thanks! 🙂

---

<div class="post-metadata">

**Author:** ![DSMilestone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsmilestone/32/73339_2.png) [@DSMilestone](https://discuss.elastic.co/u/DSMilestone)\
**Post date:** [August 23, 2020, 2:45pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/28 "2020-08-23T14:45:59Z")

</div>

Hi,  
In the csv file, there is a field called `Suite/Test/Step Name ` . Using below code I was trying to rename it in logstash conf file. Renaming worked but in kibana, it says that this new field `Test_Step_Name` is a undefined field. it doesn't allow to use this new filed to aggregate data. How to fix this?

```auto
mutate {
      rename => ["Suite/Test/Step Name", "Test_Step_Name"]
  }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 23, 2020, 2:51pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/29 "2020-08-23T14:51:46Z")

</div>

> [@DSMilestone](#):
>
> Renaming worked

What do you mean by that?

---

<div class="post-metadata">

**Author:** ![DSMilestone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsmilestone/32/73339_2.png) [@DSMilestone](https://discuss.elastic.co/u/DSMilestone)\
**Post date:** [August 23, 2020, 2:55pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/30 "2020-08-23T14:55:55Z")

</div>

Hi @Badger

I meant, in the CSV file there is a column called ` Suite/Test/Step Name` and I wanted to rename that column to a new field name called ` Test_Step_Name`.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 23, 2020, 3:03pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/31 "2020-08-23T15:03:17Z")

</div>

I would expect that mutate+rename to achieve that.

---

<div class="post-metadata">

**Author:** ![DSMilestone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsmilestone/32/73339_2.png) [@DSMilestone](https://discuss.elastic.co/u/DSMilestone)\
**Post date:** [August 23, 2020, 4:49pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/32 "2020-08-23T16:49:42Z")

</div>

Renaming works, but when I check the field in the kibana, it shows that new field as a undefined field. any idea why is that?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 23, 2020, 5:46pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/33 "2020-08-23T17:46:41Z")

</div>

Does doing a refresh of the index pattern help? I am not sure what you mean by undefined.

---

<div class="post-metadata">

**Author:** ![DSMilestone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsmilestone/32/73339_2.png) [@DSMilestone](https://discuss.elastic.co/u/DSMilestone)\
**Post date:** [August 25, 2020, 9:11am UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/34 "2020-08-25T09:11:42Z")

</div>

Refreshing didn't work. undefined meant it doesn't have a initial data type. usually for `Suite/Test/Step Name` it has the data type as ` text`. but for ` Test_Step_Name` it has the data type` ?` when I check it in kibana. Please check the below screenshot.  
 ![rsz_screenshot_14](https://us1.discourse-cdn.com/elastic/original/3X/2/d/2da6b029ee41d00964a7be9a3b8a76b0fbecd3b7.png)

---

<div class="post-metadata">

**Author:** ![DSMilestone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsmilestone/32/73339_2.png) [@DSMilestone](https://discuss.elastic.co/u/DSMilestone)\
**Post date:** [August 25, 2020, 9:19am UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/35 "2020-08-25T09:19:50Z")

</div>

And also @Badger do you know how to change the text color in kibana dashboard widgets. In the below screenshot, there are three different lens widgets in the dashboard. I want to change the text color of `Passed` count to green and `failed` count to red. How can I do that in kibana dashboard? (note: I use kibana version 7.8.0)  
 ![rsz_screenshot_15](https://us1.discourse-cdn.com/elastic/original/3X/f/b/fb8b74bb4f913002bc39a53ea9fb4a3ecbc32caf.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 25, 2020, 2:27pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/36 "2020-08-25T14:27:57Z")

</div>

I would expect refreshing the pattern to fix that. The other question is most definitely a Kibana question and I do not run Kibana, so I cannot help. Try asking in the kibana forum.

---

<div class="post-metadata">

**Author:** ![DSMilestone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsmilestone/32/73339_2.png) [@DSMilestone](https://discuss.elastic.co/u/DSMilestone)\
**Post date:** [August 25, 2020, 5:10pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/37 "2020-08-25T17:10:03Z")

</div>

OK! thank you for your support so far! 🙂

---

<div class="post-metadata">

**Author:** ![DSMilestone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsmilestone/32/73339_2.png) [@DSMilestone](https://discuss.elastic.co/u/DSMilestone)\
**Post date:** [September 5, 2020, 1:23pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/38 "2020-09-05T13:23:28Z")

</div>

Hi @Badger

In my csv file there is a column which has the katalon test case execution duration; As an example, values are like this "4.23s, 0.02s etc.". End of every value there is a char "s" to denote the seconds. How to remove this and add this particular field to float data type? Currently it saves data as "text" data type.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 5, 2020, 1:54pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/39 "2020-09-05T13:54:40Z")

</div>

```
mutate { gsub => ["someField", "s$", ""] }
mutate { convert => { "someField" => "float" } }
```

---

<div class="post-metadata">

**Author:** ![DSMilestone](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dsmilestone/32/73339_2.png) [@DSMilestone](https://discuss.elastic.co/u/DSMilestone)\
**Post date:** [September 5, 2020, 2:25pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/40 "2020-09-05T14:25:42Z")

</div>

> [@Badger](#):
>
> ```auto
> mutate { gsub => ["someField", "s$", ""] }
> mutate { convert => { "someField" => "float" } }
> 
> ```

Hi,  
Thank you for your reply. 🙂 I have added this,

```auto
  csv{
    separator => ","
    skip_header => "true"
    columns => ["Suite/Test/Step Name","Browser","Description","Tag","Start time","End time","Duration","Status"]
    skip_empty_columns => "false"
    convert => {
        "Start time" => "date_time"
        "End time" => "date_time"
    }
  }
  mutate { gsub => ["Duration", "s$", ""] }
  mutate { convert => { "Duration" => "float" } }

```

but outcome is still the same which means duration is still the same as "2.34s".

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 5, 2020, 2:34pm UTC](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806/41 "2020-09-05T14:34:59Z")

</div>

I am unable to explain that.

[Previous page](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806.md?page=1)

[Next page](https://discuss.elastic.co/t/how-to-add-first-row-first-column-value-as-a-field-in-to-other-rows-documents-of-a-csv-file-in-logstash-filters/243806.md?page=3)
