# Logstash is not able to import CSV files

**URL:** <https://discuss.elastic.co/t/logstash-is-not-able-to-import-csv-files/150480>\
**Category:** Logstash\
**Created:** [September 30, 2018, 4:38pm UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-import-csv-files/150480 "2018-09-30T16:38:41Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andy\_K](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@Andy\_K](https://discuss.elastic.co/u/Andy_K)\
**Post date:** [September 30, 2018, 4:38pm UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-import-csv-files/150480/1 "2018-09-30T16:38:41Z")

</div>

I am trying to import a CSV file to elasticsearch using logstash. There is no error displayed on the screen after running the logstash.bat. However, there is no index created in ealsticsearch. Please help.

Below is the content of the last log file.  
[2018-10-01T00:21:52,539][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.4.1"}  
[2018-10-01T00:21:59,852][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[2018-10-01T00:22:00,730][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2018-10-01T00:22:00,743][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2018-10-01T00:22:01,164][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2018-10-01T00:22:01,300][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2018-10-01T00:22:01,312][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-10-01T00:22:01,436][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2018-10-01T00:22:01,404][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost](https://localhost)"]}  
[2018-10-01T00:22:01,651][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2018-10-01T00:22:02,983][INFO][logstash.inputs.file] No sincedb\_path set, generating one based on the "path" setting {:sincedb\_path=\>"C:/Users/ahkartika/Downloads/logstash-6.4.1/data/plugins/inputs/file/.sincedb\_c810ab01ee71279c8ef52f6ad226d496", :path=\>["C:\TESLA\ELASTIC\data\cars.csv"]}  
[2018-10-01T00:22:03,053][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x6f6a12e4 run\>"}  
[2018-10-01T00:22:03,172][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>[]}  
[2018-10-01T00:22:03,173][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2018-10-01T00:22:03,845][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [September 30, 2018, 5:06pm UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-import-csv-files/150480/2 "2018-09-30T17:06:12Z")

</div>

Does your File Input configuration include a [`start_position => beginning`](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-start_position) directive? By default, when running in "tail" mode, the file input plugin only emits events for new lines that are added to the file after it has been opened.

You can also switch it to [`mode => read`](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-mode) to make it read only what is present in the file when it is opened and _not_ continue waiting for new lines to be added to the file.

You may need to delete the sincedb file in order to get the plugin to "forget" where it last left off:

```auto
C:/Users/ahkartika/Downloads/logstash-6.4.1/data/plugins/inputs/file/.sincedb_c810ab01ee71279c8ef52f6ad226d496

```

---

<div class="post-metadata">

**Author:** ![Andy\_K](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@Andy\_K](https://discuss.elastic.co/u/Andy_K)\
**Post date:** [September 30, 2018, 5:50pm UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-import-csv-files/150480/3 "2018-09-30T17:50:09Z")

</div>

Thanks for your reply.  
I have added the start\_position =\> "beginning" and mode =\> "read". I also removed "sincedb".  
It still cannot import the CSV file.

---

<div class="post-metadata">

**Author:** ![Matt\_Vasquez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_vasquez/32/22088_2.png) [@Matt\_Vasquez](https://discuss.elastic.co/u/Matt_Vasquez)\
**Post date:** [September 30, 2018, 6:42pm UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-import-csv-files/150480/4 "2018-09-30T18:42:00Z")

</div>

Are you ingesting from windows or linux? Whats your logstash config file looks like?

---

<div class="post-metadata">

**Author:** ![Andy\_K](https://avatars.discourse-cdn.com/v4/letter/a/13edae/32.png) [@Andy\_K](https://discuss.elastic.co/u/Andy_K)\
**Post date:** [October 1, 2018, 4:42pm UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-import-csv-files/150480/5 "2018-10-01T16:42:52Z")

</div>

The elasticsearch and logstash is installed in windows.  
Here is my config file:  
input {  
file {  
path =\> "C:\ELASTIC\data\cars.csv"  
start\_position =\> "beginning"   
}  
}  
filter {  
csv {  
separator =\> ","  
columns =\> ["maker", "model", "mileage", "manufacture\_year", "engine\_displacement", "engine\_power", "body\_type", "color\_slug", "stk\_year", "transmission", "door\_count", "seat\_count", "fuel\_type", "date\_created", "date\_last\_seen", "price\_eur"]  
}  
mutate {convert =\> ["milage", "integer"] }  
mutate {convert =\> ["price\_eur", "float"] }  
mutate {convert =\> ["engine\_power", "integer"] }  
mutate {convert =\> ["door\_count", "integer"] }  
mutate {convert =\> ["seat\_count", "integer"] }   
}  
output {  
elasticsearch {  
hosts =\> "localhost"  
index =\> "cars"  
document\_type =\> "sold\_cars"  
}  
stdout {}  
}

---

<div class="post-metadata">

**Author:** ![Matt\_Vasquez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/matt_vasquez/32/22088_2.png) [@Matt\_Vasquez](https://discuss.elastic.co/u/Matt_Vasquez)\
**Post date:** [October 2, 2018, 8:19pm UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-import-csv-files/150480/6 "2018-10-02T20:19:59Z")

</div>

OK yeah I had this problem the other week and spent like 2 hours trying to figure out why I couldn't ingest a simple CSV. It turns out that the path needed to be in a UNIX format (change all "\" to "/").. This seemed to change from 6.3.X to 6.4.X as the windows style path format used to work..

Change your input to:

> ```
> input {
> file {
> path => "C:/ELASTIC/data/cars.csv"
> sincedb_path => "NUL"
> start_position => "beginning"
> }
> 
> ```

---

<div class="post-metadata">

**Author:** ![edran\_zy](https://avatars.discourse-cdn.com/v4/letter/e/898d66/32.png) [@edran\_zy](https://discuss.elastic.co/u/edran_zy)\
**Post date:** [October 3, 2018, 3:51am UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-import-csv-files/150480/7 "2018-10-03T03:51:49Z")

</div>

I am getting the same error on 6.4.1 logstash, but it working on 6.0.0 logstash.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 31, 2018, 3:51am UTC](https://discuss.elastic.co/t/logstash-is-not-able-to-import-csv-files/150480/8 "2018-10-31T03:51:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
