# Let CSV columns be fields

**URL:** <https://discuss.elastic.co/t/let-csv-columns-be-fields/188403>\
**Category:** Logstash\
**Created:** [July 1, 2019, 8:25pm UTC](https://discuss.elastic.co/t/let-csv-columns-be-fields/188403 "2019-07-01T20:25:51Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Adolfo\_Herrera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adolfo_herrera/32/49205_2.png) [@Adolfo\_Herrera](https://discuss.elastic.co/u/Adolfo_Herrera)\
**Post date:** [July 1, 2019, 8:25pm UTC](https://discuss.elastic.co/t/let-csv-columns-be-fields/188403/1 "2019-07-01T20:25:52Z")

</div>

Hello I'm trying to get the names of the columns from my csv file to become field names. However, they all seem to be staying in the message field

```
input
{
    beats {
            port => 5044
    }
}
filter
{
    csv {
            columns => ["Package","Class","Test","10"]
            separator => ","
        }
}
output
{
    stdout {
            codec => rubydebug
    }

    elasticsearch {
            hosts => ["http://localhost:9200"]
            index => "csv-data-2019"
    }
}

```

 ![problem](https://us1.discourse-cdn.com/elastic/original/3X/5/5/5585cc6c8eef8ec70bbc64d1164e9c282d7a53a1.png)

---

<div class="post-metadata">

**Author:** ![Juanma](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/juanma/32/49076_2.png) [@Juanma](https://discuss.elastic.co/u/Juanma)\
**Post date:** [July 1, 2019, 9:35pm UTC](https://discuss.elastic.co/t/let-csv-columns-be-fields/188403/2 "2019-07-01T21:35:11Z")

</div>

Hi

Its the CSV comming in "message" field?  
If not, you need yo specify a source field with "field" parameter.

Could you post an example if the stdout output without the CSV filter?

---

<div class="post-metadata">

**Author:** ![Adolfo\_Herrera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adolfo_herrera/32/49205_2.png) [@Adolfo\_Herrera](https://discuss.elastic.co/u/Adolfo_Herrera)\
**Post date:** [July 1, 2019, 10:28pm UTC](https://discuss.elastic.co/t/let-csv-columns-be-fields/188403/3 "2019-07-01T22:28:29Z")

</div>

How do I go about specifying a source field?

I got rid of the CSV filter and the output stayed the same.

 ![problem2](https://us1.discourse-cdn.com/elastic/original/3X/e/a/eaf39a91279a84750e800923264965f69b8a1378.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 1, 2019, 10:39pm UTC](https://discuss.elastic.co/t/let-csv-columns-be-fields/188403/4 "2019-07-01T22:39:48Z")

</div>

I would not expect the message field to change just because you are using a csv filter, however, I would expect with the filter you show that the event would have [Package], [Class], [Test], and [10] fields added.

If that did not happen, and you did not get a parse failure then that really suggests you were not running with the configuration you thought you had in place. How are you starting logstash?

Can you add '--log.level debug --config.debug' to your command line? That will cause it to log the actual configuration it is running with.

---

<div class="post-metadata">

**Author:** ![Adolfo\_Herrera](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adolfo_herrera/32/49205_2.png) [@Adolfo\_Herrera](https://discuss.elastic.co/u/Adolfo_Herrera)\
**Post date:** [July 2, 2019, 4:10pm UTC](https://discuss.elastic.co/t/let-csv-columns-be-fields/188403/5 "2019-07-02T16:10:28Z")

</div>

It was my mistake I was going straight to elasticsearch from filebeat and not sending it to logstash. I have fixed that now on the filebeat.yml fille.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 30, 2019, 4:10pm UTC](https://discuss.elastic.co/t/let-csv-columns-be-fields/188403/6 "2019-07-30T16:10:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
