# Logstash index to come from a csv field

**URL:** <https://discuss.elastic.co/t/logstash-index-to-come-from-a-csv-field/101234>\
**Category:** Logstash\
**Created:** [September 20, 2017, 9:18pm UTC](https://discuss.elastic.co/t/logstash-index-to-come-from-a-csv-field/101234 "2017-09-20T21:18:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![dorj1234](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorj1234/32/21339_2.png) [@dorj1234](https://discuss.elastic.co/u/dorj1234)\
**Post date:** [September 20, 2017, 9:18pm UTC](https://discuss.elastic.co/t/logstash-index-to-come-from-a-csv-field/101234/1 "2017-09-20T21:18:00Z")

</div>

Hello,  
I have a field with columns A,B,C where A represents the source of the file.  
Many sources send csv files to one location and the index should be according to the source.

For example:  
file1.csv  
A=source1 --\> index should be "source1"

file2.csv  
A=source2 --\> index should be "source2"

Note that all rows in the csv file will contain the same info, so it's ok to choose any of the rows for creating the index.  
Looks like the index is either hard-coded or derived from system fields, not from content fields. I hope it's possible because if not I'll have to engineer my solution completely differently and run multiple logstashes and separate every source to a separate location just to have separate indexes, which is a waste of resources.

Thanks in advance for any advice!  
JD

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 21, 2017, 4:05am UTC](https://discuss.elastic.co/t/logstash-index-to-come-from-a-csv-field/101234/2 "2017-09-21T04:05:05Z")

</div>

If you create the A column into a field called (eg) `source`, then just do this in [the output](https://www.elastic.co/guide/en/logstash/5.6/plugins-outputs-elasticsearch.html#plugins-outputs-elasticsearch-index);

```auto
index => "%{source}-%{+YYYY.MM.dd}"

```

---

<div class="post-metadata">

**Author:** ![dorj1234](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dorj1234/32/21339_2.png) [@dorj1234](https://discuss.elastic.co/u/dorj1234)\
**Post date:** [October 6, 2017, 2:32pm UTC](https://discuss.elastic.co/t/logstash-index-to-come-from-a-csv-field/101234/3 "2017-10-06T14:32:40Z")

</div>

Thank you ! worked like a charm

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 3, 2017, 2:33pm UTC](https://discuss.elastic.co/t/logstash-index-to-come-from-a-csv-field/101234/4 "2017-11-03T14:33:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
