# Logstash Filter CSV - Multiple Header

**URL:** <https://discuss.elastic.co/t/logstash-filter-csv-multiple-header/159147>\
**Category:** Logstash\
**Created:** [December 3, 2018, 10:51am UTC](https://discuss.elastic.co/t/logstash-filter-csv-multiple-header/159147 "2018-12-03T10:51:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![cmcdowell03](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cmcdowell03/32/36369_2.png) [@cmcdowell03](https://discuss.elastic.co/u/cmcdowell03)\
**Post date:** [December 3, 2018, 10:51am UTC](https://discuss.elastic.co/t/logstash-filter-csv-multiple-header/159147/1 "2018-12-03T10:51:02Z")

</div>

Hello,  
I am trying to parse a relatively complex .csv file with mulitple header lines. I am curious if there has been any headway on this issue or if there is a clever work around. I don't have an issue filtering the header lines into Elasticsearch, my issue is associating the following data lines to the headers that have been filtered. An example of the data goes as follows

Header1,Header2,Header3,Header4  
1,2,3,4  
5,6,7,8  
Header11,Header12,Header13,Header14,Header15  
1,2,3,4,5  
6,7,8,3,1

When I utilized the autodetect\_column\_names =\> true feature only the columns are created but the following data does not relate. It would be nice if there was a way to insert these read columns into an object for the columns =\> filter. Any help is appreciated.. Thank you

Edit:  
I understand the CSV filter is stateless from this previous discussion

> [@Reading the heading (1st line) of CSV file through logstash](https://discuss.elastic.co/t/reading-the-heading-1st-line-of-csv-file-through-logstash/108930/5):
>
> Thanks @guyboertje for you quick response.. As per your queries below: How many different CSV structures do you need to parse? \> There is no limit for CSV structures, at present we have done for 2 but in future we are expecting more, so would like to generalize for all the structures. Does the filename and/or path contain a clue to the type of CSV structure? \> Yes, filepath can be in one location(we can hard code the path) but filename varies.

I would assume there are many people who have run across this issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2018, 10:51am UTC](https://discuss.elastic.co/t/logstash-filter-csv-multiple-header/159147/2 "2018-12-31T10:51:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
