# I cannot see every column or see wrong output for the exisiting ones

**URL:** <https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343>\
**Category:** Logstash\
**Created:** [April 29, 2020, 9:18am UTC](https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343 "2020-04-29T09:18:05Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Burak\_Sakallioglu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/burak_sakallioglu/32/47806_2.png) [@Burak\_Sakallioglu](https://discuss.elastic.co/u/Burak_Sakallioglu)\
**Post date:** [April 29, 2020, 9:18am UTC](https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343/1 "2020-04-29T09:18:05Z")

</div>

Hi everyone,

I have been trying to import my csv file with logstash, however, the output is not seen as I expected.  
Firstly, I cannot see every column in the output, then I cannot see the correct value for some existing columns in the output.

My config file is:

```
> input {
> file {
> path => "/home/burak/Downloads/QA2/*"
> start_position => "beginning"
> sincedb_path => "/dev/null"
> }
> }
> filter {
> csv {
> separator => ","
> columns => ["Epic","Total User Stories","Closed User Stories","Not Closed User Stories","User Stories with Test Case Creation in Progress","Total Test Cases Forecast","Total Created Test Cases","Total Executed","Pass","Fail","Blocked","NA"]
> }
> }
> output {
> elasticsearch {
> hosts => "http://localhost:9200"
> index => "qadata"
> }
> stdout {}
> }

```

This is a simple output:

```
{
                                      "Total User Stories" => "83;318;231;194;33;4;0;87;87;54",
                                                    "path" => "/home/burak/Downloads/QA2/qadata.csv",
                                              "@timestamp" => 2020-04-29T08:51:11.946Z,
                         "User Stories Without Test Cases" => "97;1",
                                                    "Epic" => ";236;129;107;29;5;0;372",
        "User Stories with Test Case Creation in Progress" => "25;2020-04-17",
                                                    "host" => "burak-VirtualBox",
                                                 "message" => ";236;129;107;29;5;0;372,83;318;231;194;33;4;0;87;87;54,83;178,83;161;137;24;4;17;3;0,7;10,97;1,25;2020-04-17\r",
                                 "Not Closed User Stories" => "83;161;137;24;4;17;3;0",
                                     "Closed User Stories" => "83;178",
                      "User Stories with Test Cases Ready" => "7;10",
                                                "@version" => "1"
    }

```

There are many fields that I did not show it here but basically it's like this.  
I'm new in ELK I may do simple mistakes.

OS: Ubuntu 18.04.4 LTS  
ElasticSearch: 7.6.2  
Logstash: 7.6.2

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 29, 2020, 1:15pm UTC](https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343/2 "2020-04-29T13:15:24Z")

</div>

What is your question?

---

<div class="post-metadata">

**Author:** ![Burak\_Sakallioglu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/burak_sakallioglu/32/47806_2.png) [@Burak\_Sakallioglu](https://discuss.elastic.co/u/Burak_Sakallioglu)\
**Post date:** [April 29, 2020, 1:18pm UTC](https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343/3 "2020-04-29T13:18:55Z")

</div>

Sorry, I should have been clear. My question is why I cannot see all fields in my .csv file when I used logstash to import it.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 29, 2020, 1:32pm UTC](https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343/4 "2020-04-29T13:32:48Z")

</div>

> [@Burak\_Sakallioglu](#):
>
> "message" =\> ";236;129;107;29;5;0;372,83;318;231;194;33;4;0;87;87;54,83;178,83;161;137;24;4;17;3;0,7;10,97;1,25;2020-04-17\r",

Your [message] has six commas in it and the csv filter parsed it into seven fields. I have no idea how you could expect anything more.

---

<div class="post-metadata">

**Author:** ![Burak\_Sakallioglu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/burak_sakallioglu/32/47806_2.png) [@Burak\_Sakallioglu](https://discuss.elastic.co/u/Burak_Sakallioglu)\
**Post date:** [April 29, 2020, 1:36pm UTC](https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343/5 "2020-04-29T13:36:11Z")

</div>

If you check here ;

```auto
> filter {
> csv {
> separator => ","
> columns => ["Epic","Total User Stories","Closed User Stories","Not Closed User Stories","User Stories with Test Case Creation in Progress","Total Test Cases Forecast","Total Created Test Cases","Total Executed","Pass","Fail","Blocked","NA"]
> }
> }

```

I have 12 columns but I can't see any field such as Pass, Fail etc. when I used logstash

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 29, 2020, 1:38pm UTC](https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343/6 "2020-04-29T13:38:33Z")

</div>

As I said, your message field only has 6 commas in it, so you will only get 7 fields.

---

<div class="post-metadata">

**Author:** ![Burak\_Sakallioglu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/burak_sakallioglu/32/47806_2.png) [@Burak\_Sakallioglu](https://discuss.elastic.co/u/Burak_Sakallioglu)\
**Post date:** [April 29, 2020, 1:41pm UTC](https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343/7 "2020-04-29T13:41:42Z")

</div>

OK. So why do I have 6 commas in message?  
Sorry, if this is a silly question, I'm quite new. From my searches, I found that I should use the above config to import my csv file. I would expect I should see whole 12 columns in the output as a field.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 29, 2020, 1:48pm UTC](https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343/8 "2020-04-29T13:48:08Z")

</div>

The csv filter will not create fields that do not exist in the file that you are processing.

---

<div class="post-metadata">

**Author:** ![Burak\_Sakallioglu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/burak_sakallioglu/32/47806_2.png) [@Burak\_Sakallioglu](https://discuss.elastic.co/u/Burak_Sakallioglu)\
**Post date:** [April 29, 2020, 1:54pm UTC](https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343/9 "2020-04-29T13:54:09Z")

</div>

I have these fields in the file that is the confusing part for me. I did not add anything that doesn't exist in the file I've been using.

---

<div class="post-metadata">

**Author:** ![Burak\_Sakallioglu](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/burak_sakallioglu/32/47806_2.png) [@Burak\_Sakallioglu](https://discuss.elastic.co/u/Burak_Sakallioglu)\
**Post date:** [May 3, 2020, 1:30pm UTC](https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343/10 "2020-05-03T13:30:20Z")

</div>

does anyone can help me on this issue?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2020, 1:30pm UTC](https://discuss.elastic.co/t/i-cannot-see-every-column-or-see-wrong-output-for-the-exisiting-ones/230343/11 "2020-05-31T13:30:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
