# Logstash not responding when import csv

**URL:** <https://discuss.elastic.co/t/logstash-not-responding-when-import-csv/142149>\
**Category:** Logstash\
**Created:** [July 30, 2018, 10:41am UTC](https://discuss.elastic.co/t/logstash-not-responding-when-import-csv/142149 "2018-07-30T10:41:37Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![jibinoosae](https://avatars.discourse-cdn.com/v4/letter/j/858c86/32.png) [@jibinoosae](https://discuss.elastic.co/u/jibinoosae)\
**Post date:** [July 30, 2018, 10:41am UTC](https://discuss.elastic.co/t/logstash-not-responding-when-import-csv/142149/1 "2018-07-30T10:41:37Z")

</div>

i am not able to get import the CSV file with below configuration

input{  
file{  
path =\> "C:\change\_reque07.csv"  
start\_position =\> "beginning"  
}  
}  
filter{  
csv{  
separator =\> ","  
columns =\> ["company","number","requested\_by","u\_category","u\_rfc","u\_device\_ref\_1","u\_service\_impact","u\_urgency\_lead\_time","requested\_by\_date","sys\_created\_on","closed\_at","u\_stage","state","u\_machx\_case\_reference","sys\_updated\_on","sys\_updated\_by","requested\_by.company","sys\_created\_by","opened\_at","opened\_by","closed\_by","u\_machx\_success\_date","u\_change\_ack\_time","u\_change\_successful","u\_device\_1","u\_device\_ref\_2","u\_device\_2","u\_device\_ref\_3","u\_device\_3","u\_device\_ref\_4","u\_device\_4","u\_device\_ref\_5","u\_device\_5","u\_device\_ref\_6"]  
}  
}  
output {  
elasticsearch {  
hosts =\> "[http://localhost:9200](http://localhost:9200)"  
index =\> "cr-02"  
}  
stdout {}  
}

cmd logs is as follows its stuck at the end:

C:\Kibana\logstash-6.2.3\bin\>logstash -f logstash.conf  
Sending Logstash's logs to C:/Kibana/logstash-6.2.3/logs which is now configured via log4j2.properties  
[2018-07-30T15:49:19,204][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"fb\_apache", :directory=\>"C:/Kibana/logstash-6.2.3/modules/fb\_apache/configuration"}  
[2018-07-30T15:49:19,313][INFO][logstash.modules.scaffold] Initializing module {:module\_name=\>"netflow", :directory=\>"C:/Kibana/logstash-6.2.3/modules/netflow/configuration"}  
[2018-07-30T15:49:19,858][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2018-07-30T15:49:21,549][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.2.3"}  
[2018-07-30T15:49:22,377][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}  
[2018-07-30T15:49:29,179][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>4, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[2018-07-30T15:49:30,192][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>[], :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2018-07-30T15:49:30,214][INFO][logstash.outputs.elasticsearch] Running health check to see if an Elasticsearch connection is working {:healthcheck\_url=\>[http://localhost:9200/](http://localhost:9200/), :path=\>"/"}  
[2018-07-30T15:49:30,856][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2018-07-30T15:49:30,990][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2018-07-30T15:49:31,001][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2018-07-30T15:49:31,037][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2018-07-30T15:49:31,133][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2018-07-30T15:49:31,247][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[http://localhost:9200](http://localhost:9200)"]}  
[2018-07-30T15:49:33,095][INFO][logstash.pipeline] Pipeline started succesfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x53cf0cd0 run\>"}  
[2018-07-30T15:49:33,362][INFO][logstash.agent] Pipelines running {:count=\>1, :pipelines=\>["main"]}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 30, 2018, 1:21pm UTC](https://discuss.elastic.co/t/logstash-not-responding-when-import-csv/142149/2 "2018-07-30T13:21:51Z")

</div>

A file input will tail the input forever, waiting for new lines to be appended. So this looks normal.

start\_position only has any effect the first time you run an input with that configuration. Adding this to the file input might help

```
sincedb_path => "NUL"
```

---

<div class="post-metadata">

**Author:** ![rijinmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rijinmp/32/24634_2.png) [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Post date:** [July 30, 2018, 1:43pm UTC](https://discuss.elastic.co/t/logstash-not-responding-when-import-csv/142149/3 "2018-07-30T13:43:21Z")

</div>

Did your config file is added to logstash.yml ?

---

<div class="post-metadata">

**Author:** ![jibinoosae](https://avatars.discourse-cdn.com/v4/letter/j/858c86/32.png) [@jibinoosae](https://discuss.elastic.co/u/jibinoosae)\
**Post date:** [July 31, 2018, 5:40am UTC](https://discuss.elastic.co/t/logstash-not-responding-when-import-csv/142149/4 "2018-07-31T05:40:34Z")

</div>

no, is it compalsory?

---

<div class="post-metadata">

**Author:** ![jibinoosae](https://avatars.discourse-cdn.com/v4/letter/j/858c86/32.png) [@jibinoosae](https://discuss.elastic.co/u/jibinoosae)\
**Post date:** [July 31, 2018, 6:28am UTC](https://discuss.elastic.co/t/logstash-not-responding-when-import-csv/142149/5 "2018-07-31T06:28:54Z")

</div>

The following error i got here after add \>\> sincedb\_path =\> "NUL"

[2018-07-31T11:51:35,253][INFO][logstash.agent] Pipelines running {:count=\>1, :pipelines=\>["main"]}  
[2018-07-31T11:51:43,542][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"cr-02", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x65f3db4], :response=\>{"index"=\>{"\_index"=\>"cr-02", "\_type"=\>"doc", "\_id"=\>"xkb\_7mQB4saQgjbI3siQ", "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"mapper [requested\_by] of different type, current\_type [text], merged\_type [ObjectMapper]"}}}}

also

[2018-07-31T16:44:17,160][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=\>400, :action=\>["index", {:\_id=\>nil, :\_index=\>"cr-011", :\_type=\>"doc", :\_routing=\>nil}, #LogStash::Event:0x7222c5b0], :response=\>{"index"=\>{"\_index"=\>"cr-011", "\_type"=\>"doc", "\_id"=\>"XsEL8GQB4827YA68s15F", "status"=\>400, "error"=\>{"type"=\>"illegal\_argument\_exception", "reason"=\>"Can't merge a non object mapping [requested\_by] with an object mapping [requested\_by]

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [July 31, 2018, 11:56am UTC](https://discuss.elastic.co/t/logstash-not-responding-when-import-csv/142149/6 "2018-07-31T11:56:26Z")

</div>

That's a good thing, it indicates it is reading events from the file and trying to index them into elasticsearch.

If you add 'output { stdout { codec =\> rubydebug } }' to your logstash configuration, what does the 'requested\_by' field look like. Also, if you go to the Discover pane in Kibana and look at a document that has already been indexed, what does the 'requested\_by' field look like? Copy and past it from the JSON tab on an expanded document.

---

<div class="post-metadata">

**Author:** ![rijinmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rijinmp/32/24634_2.png) [@rijinmp](https://discuss.elastic.co/u/rijinmp)\
**Post date:** [August 9, 2018, 10:37am UTC](https://discuss.elastic.co/t/logstash-not-responding-when-import-csv/142149/7 "2018-08-09T10:37:34Z")

</div>

Some times

Please add your filter config file's path to logstash.yml as mentioned below

path.config: /home/logstash/logstash-6.2.2/config/myfilter.config

myfilter.config is your filter file and it is placed in config folder of logstash

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 6, 2018, 10:50am UTC](https://discuss.elastic.co/t/logstash-not-responding-when-import-csv/142149/8 "2018-09-06T10:50:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
