# Logstash CSV mutate, split and filter

**URL:** <https://discuss.elastic.co/t/logstash-csv-mutate-split-and-filter/301084>\
**Category:** Logstash\
**Created:** [March 30, 2022, 12:34pm UTC](https://discuss.elastic.co/t/logstash-csv-mutate-split-and-filter/301084 "2022-03-30T12:34:57Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [March 30, 2022, 12:34pm UTC](https://discuss.elastic.co/t/logstash-csv-mutate-split-and-filter/301084/1 "2022-03-30T12:34:57Z")

</div>

Hello,

I hope my message finds the Elastic community safe and healthy.

I am trying to import CSV files wherein I want to **create a _new_ field** - `tld` using data **from one of the columns** being imported.

**Source Column name:** domain\_name  
**Data will have "." as a separator:** example: [bbc.co.uk](http://bbc.co.uk) or simpler [bbcnews.com](http://bbcnews.com)  
**New field name:** `tld` - Hence using the example tld should hold `.co.uk or .com`

In both cases I want to create a new field "tld" from domain\_name with data after the first "." reading from left to right. Hence I wrote the following configuration but static text got added to "tld".

```auto
filter {
        csv {
                skip_header => "true"
                columns => ["num","domain_name","query_time","create_date","update_date","expiry_date","domain_registrar_id","domain_registrar_name","domai> remove_field => ["num"]
                }
        mutate {
                add_field => { "tld1" => "%{domain_name}" }
                split => { "tld1" => "." }
                add_field => { "tld" => "%{[tld1][1]}" }
                remove_field => ["tld1"]
                }
        }

```

My current configuration returns the value `"%{[tld1][1]}"` for tld in all the entires being imported. I am not sure but is my filter being taken as a string?

I followed the example here: [Mutate filter plugin | Logstash Reference [8.1] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-mutate.html#plugins-filters-mutate-add_field)

I am currently running version 7.17.1 of the stack.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [March 30, 2022, 1:49pm UTC](https://discuss.elastic.co/t/logstash-csv-mutate-split-and-filter/301084/2 "2022-03-30T13:49:39Z")

</div>

You need to use differente mutates, you can't add a field in a mutate and do another operation with the same field in the same mutate.

There is a note in the documentation about it:

> Each mutation must be in its own code block if the sequence of operations needs to be preserved.

This is your case since the operations needs to follow a sequence.

Try the following:

```auto
mutate {
    add_field => { "tld1" => "%{[domain_name]}" }
}
mutate {
    split => { "tld1" => "." }
}
mutate {
    add_field => { "tld" => "%{[tld1][1]}"  
}
mutate {
    remove_field => ["tld1"]
}

```

---

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [March 30, 2022, 3:34pm UTC](https://discuss.elastic.co/t/logstash-csv-mutate-split-and-filter/301084/3 "2022-03-30T15:34:43Z")

</div>

Very sorry for that. I feel ashamed being in the TL:DR group :). I'll pay more attention henceforth :). Thank you very much.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 30, 2022, 5:47pm UTC](https://discuss.elastic.co/t/logstash-csv-mutate-split-and-filter/301084/4 "2022-03-30T17:47:36Z")

</div>

> [@parthmaniar](#):
>
> tld should hold `.co.uk or .com`

I just answered a similar question [here](https://discuss.elastic.co/t/keep-only-domain-tld-in-field-with-various-subdomains/301097/2). A general solution to this problem is ridiculously complicated.

---

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [March 31, 2022, 10:55am UTC](https://discuss.elastic.co/t/logstash-csv-mutate-split-and-filter/301084/5 "2022-03-31T10:55:12Z")

</div>

Hello,

I made the changes as suggested (I am still working on how to manage TLDs having multiple .'s [like .co.uk]

Here is my current configuration:

```auto
filter {
        csv {
                skip_header => "true"
                columns => ["num","domain_name","query_time","create_date","update_date","expiry_date","domain_registrar_id","domain_registrar_name","domain_registrar_whois","domain_registrar_url","registrant_name","registrant_company","registrant_address","registrant_> remove_field => ["num"]
            }
        mutate {
                add_field => { "tld1" => "%{[domain_name]}" }
        }
        mutate {
                split => { "tld1" => "." }
        }
        mutate {
                add_field => { "tld" => "%{[tld1][1]}"
        }
        mutate {
                remove_field => ["tld1"]
        }
}

```

Here is the error I get when running the configuration check:

**Reason: Expected one of [\t\r\n], "#", "=\>" at line 23, column 9 (byte 1389) after filter {**

```auto
[FATAL] 2022-03-31 10:51:43.603 [LogStash::Runner] runner - The given configuration is invalid. Reason: Expected one of [\t\r\n], "#", "=>" at line 23, column 9 (byte 1389) after filter {
        csv {
                skip_header => "true"
                columns => ["num","domain_name","query_time","create_date","update_date","expiry_date","domain_registrar_id","domain_registrar_name","domain_registrar_whois","domain_registrar_url","registrant_name","registrant_company","registrant_address","registrant_city","registrant_state","registrant_zip","registrant_country","registrant_email","registrant_phone","registrant_fax","administrative_name","administrative_company","administrative_address","administrative_city","administrative_state","administrative_zip","administrative_country","administrative_email","administrative_phone","administrative_fax","technical_name","technical_company","technical_address","technical_city","technical_state","technical_zip","technical_country","technical_email","technical_phone","technical_fax","billing_name","billing_company","billing_address","billing_city","billing_state","billing_zip","billing_country","billing_email","billing_phone","billing_fax","name_server_1","name_server_2","name_server_3","name_server_4","domain_status_1","domain_status_2","domain_status_3","domain_status_4"]
                remove_field => ["num"]
                  }
        mutate {
                add_field => { "tld1" => "%{[domain_name]}" }
                }
        mutate {
                split => { "tld1" => "." }
                }
        mutate {
                add_field => { "tld" => "%{[tld1][1]}"
                }
        mutate
[FATAL] 2022-03-31 10:51:43.612 [LogStash::Runner] Logstash - Logstash stopped processing because of an error: (SystemExit) exit
org.jruby.exceptions.SystemExit: (SystemExit) exit
        at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:747) ~[jruby-complete-9.2.20.1.jar:?]
        at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:710) ~[jruby-complete-9.2.20.1.jar:?]
        at usr.share.logstash.lib.bootstrap.environment.<main>(/usr/share/logstash/lib/bootstrap/environment.rb:94) ~[?:?]

```

---

<div class="post-metadata">

**Author:** ![parthmaniar](https://avatars.discourse-cdn.com/v4/letter/p/71e660/32.png) [@parthmaniar](https://discuss.elastic.co/u/parthmaniar)\
**Post date:** [April 23, 2022, 9:44am UTC](https://discuss.elastic.co/t/logstash-csv-mutate-split-and-filter/301084/6 "2022-04-23T09:44:15Z")

</div>

Thank you very much, both the solutions work perfectly. 🙂

I did have it easy that I don't have subdomains as part of my dataset. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 21, 2022, 9:44am UTC](https://discuss.elastic.co/t/logstash-csv-mutate-split-and-filter/301084/7 "2022-05-21T09:44:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
