# Logstash read csv column problem

**URL:** <https://discuss.elastic.co/t/logstash-read-csv-column-problem/168335>\
**Category:** Logstash\
**Created:** [February 14, 2019, 6:07am UTC](https://discuss.elastic.co/t/logstash-read-csv-column-problem/168335 "2019-02-14T06:07:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![CCH0124](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cch0124/32/36436_2.png) [@CCH0124](https://discuss.elastic.co/u/CCH0124)\
**Post date:** [February 14, 2019, 6:07am UTC](https://discuss.elastic.co/t/logstash-read-csv-column-problem/168335/1 "2019-02-14T06:07:26Z")

</div>

I added `autodetect_column_names` to the csv block on the filter to automatically detect the head value, but the index on kibana appears column2, column3 ... , what is the cause?

config

```auto
nput {
        file {
                path => ["/usr/share/logstash/DataSet/TBrain_IPS.csv"]
                close_older => 3600
                codec => "plain"
                delimiter => "n"
                discover_interval => 30
                enable_metric => true
                id => "ips"
                max_open_files => 5
                sincedb_path => "/dev/null"
                sincedb_write_interval => 15
                start_position => "beginning"
                stat_interval => 7200
                tags => "ips"
                type => "ips"
        }
}
filter {
        csv {
                separator => ","
                autodetect_column_names=> true
                skip_empty_columns=> false
                skip_empty_rows=> false
                skip_header=> false
                periodic_flush => true
                id => "csv"
        }
        if [tags] == "ips" {
                mutate {
                        convert => {
                                "event_protocol_id" => "integer"
                        }
                        rename => {
                                "event_rule_reference" => "event_rule_referenceCVE"
                        }
                        split => {
                                "event_rule_reference" => ";"
                        }
                }

        }

}
output {
        elasticsearch {
                hosts => "elasticsearch:9200"
                document_type => "ips-csv"
                index => "ips-%{+YYYY.MM.dd}"
        }
        stdout {
                 codec => rubydebug
        }
}

```

---

<div class="post-metadata">

**Author:** ![danhermann](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/danhermann/32/33024_2.png) [@danhermann](https://discuss.elastic.co/u/danhermann)\
**Post date:** [February 14, 2019, 3:39pm UTC](https://discuss.elastic.co/t/logstash-read-csv-column-problem/168335/2 "2019-02-14T15:39:09Z")

</div>

The `autodetect_column_names` option on the CSV filter work reliably only if you set the number of worker threads to 1. With more than one worker thread, there's a race condition in which an indeterminate row will be selected as the header row. There's a [bug](https://github.com/logstash-plugins/logstash-filter-csv/issues/65) filed on the CSV filter for that, but a fix is very difficult.

---

<div class="post-metadata">

**Author:** ![CCH0124](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cch0124/32/36436_2.png) [@CCH0124](https://discuss.elastic.co/u/CCH0124)\
**Post date:** [February 15, 2019, 5:13am UTC](https://discuss.elastic.co/t/logstash-read-csv-column-problem/168335/3 "2019-02-15T05:13:35Z")

</div>

Can I currently only specify with columns and pipline.work?  
Still have a better way to solve it ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 15, 2019, 5:25am UTC](https://discuss.elastic.co/t/logstash-read-csv-column-problem/168335/4 "2019-03-15T05:25:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
