# Logstash import two columns

**URL:** <https://discuss.elastic.co/t/logstash-import-two-columns/262236>\
**Category:** Logstash\
**Created:** [January 26, 2021, 1:47pm UTC](https://discuss.elastic.co/t/logstash-import-two-columns/262236 "2021-01-26T13:47:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Farid\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farid_n/32/74144_2.png) [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Post date:** [January 26, 2021, 1:47pm UTC](https://discuss.elastic.co/t/logstash-import-two-columns/262236/1 "2021-01-26T13:47:08Z")

</div>

Hi  
I use JDBC driver to connect Logstash with a data base and run a SP in statement.  
the result of SP is one number(integer) and two columns.  
I want to send these into one log in Elasticsearch

Could you please tell me how can I write the filter?  
For example: I wrote this for the integer:

```auto
filter {
    mutate {
        add_field => {count => "%{untitled}"}
        convert => {count => integer}

```

What can I do for two columns?!?

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [January 27, 2021, 5:24am UTC](https://discuss.elastic.co/t/logstash-import-two-columns/262236/2 "2021-01-27T05:24:24Z")

</div>

Hi Farid,

To better understand the question, you run a SP, and it gives you a total of 3 columns in a single event. One column is an integer and the other two columns are not an integer?

What happens if you index this event? How does it look in ES?

---

<div class="post-metadata">

**Author:** ![Farid\_N](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farid_n/32/74144_2.png) [@Farid\_N](https://discuss.elastic.co/u/Farid_N)\
**Post date:** [January 27, 2021, 6:03am UTC](https://discuss.elastic.co/t/logstash-import-two-columns/262236/3 "2021-01-27T06:03:01Z")

</div>

Thank you NerdSec for your response.  
No, actually the SP from data base returns 3things:  
one number and two columns  
I know how to filter my number(as I wrote before)  
But I do not know how to filter and change the name of columns, or separate the values in one column. For example shall I do this?!?

```auto
filter {
    mutate {
        split => { "fieldname" => "," }
    }
}

```

All in all if I want to wrap everything up, I did not faced a column to index to Elasticsearch. I already import a log(just an integer number) via Logstash but I have not experience with how to import a column (or maybe a string) into elastcisearch

---

<div class="post-metadata">

**Author:** ![NerdSec](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/nerdsec/32/22056_2.png) [@NerdSec](https://discuss.elastic.co/u/NerdSec)\
**Post date:** [January 27, 2021, 6:08am UTC](https://discuss.elastic.co/t/logstash-import-two-columns/262236/4 "2021-01-27T06:08:46Z")

</div>

I'm sorry, I couldn't quite understand the scenario.

> [@NerdSec](#):
>
> What happens if you index this event? How does it look in ES?

Could you post some dummy data of how it looks in ES? And how do you want it? This would be a lot easier

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 24, 2021, 6:08am UTC](https://discuss.elastic.co/t/logstash-import-two-columns/262236/5 "2021-02-24T06:08:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
