# Logstash reading the file line multiple times

**URL:** <https://discuss.elastic.co/t/logstash-reading-the-file-line-multiple-times/185201>\
**Category:** Logstash\
**Created:** [June 11, 2019, 1:44pm UTC](https://discuss.elastic.co/t/logstash-reading-the-file-line-multiple-times/185201 "2019-06-11T13:44:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tania\_Saez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tania_saez/32/47626_2.png) [@Tania\_Saez](https://discuss.elastic.co/u/Tania_Saez)\
**Post date:** [June 11, 2019, 1:44pm UTC](https://discuss.elastic.co/t/logstash-reading-the-file-line-multiple-times/185201/1 "2019-06-11T13:44:39Z")

</div>

Hello,

In my logstash installation, it is reading a csv file to insert it in elasticsearch. It should read each line just one time, but in fact is reading/processing up to 4 times:  
{  
"@version" =\> "1",  
"endpoint" =\> "/managetv/tvrecord/recordings/filterByPage",  
"total\_response\_time" =\> 164.0,  
"send\_body\_ms" =\> 0.003814697265625,  
"@timestamp" =\> 2019-06-11T13:40:56.521Z,  
"wait\_for\_response\_ms" =\> 58.86197090148926,  
"dial\_ms" =\> 33.52546691894531,  
"path" =\> "/home/tania/runscope\_csv/extract\_data.csv",  
"dns\_lookup\_ms" =\> 8.34965705871582,  
"host" =\> "MAD00303",  
"receive\_response\_ms" =\> 0.06461143493652344,  
"code\_status" =\> " 200",  
"message" =\> "/managetv/tvrecord/recordings/filterByPage, mar jun 11 15:36:49 DST 2019, 200, 164.0, 70.96147537231445, 33.52546691894531, 0.003814697265625, 58.86197090148926, 8.34965705871582, 0.06461143493652344 ",  
"send\_headers\_ms" =\> 70.96147537231445  
}  
{  
"@version" =\> "1",  
"code\_status" =\> " 200",  
"dns\_lookup\_ms" =\> 8.34965705871582,  
"total\_response\_time" =\> 164.0,  
"send\_body\_ms" =\> 0.003814697265625,  
"endpoint" =\> "/managetv/tvrecord/recordings/filterByPage",  
"message" =\> "/managetv/tvrecord/recordings/filterByPage, mar jun 11 15:36:49 DST 2019, 200, 164.0, 70.96147537231445, 33.52546691894531, 0.003814697265625, 58.86197090148926, 8.34965705871582, 0.06461143493652344 ",  
"@timestamp" =\> 2019-06-11T13:40:56.678Z,  
"send\_headers\_ms" =\> 70.96147537231445,  
"path" =\> "/home/tania/runscope\_csv/extract\_data.csv",  
"wait\_for\_response\_ms" =\> 58.86197090148926,  
"host" =\> "MAD00303",  
"dial\_ms" =\> 33.52546691894531,  
"receive\_response\_ms" =\> 0.06461143493652344

My logshtash configuration is:

input {  
file {  
path =\> "/home/tania/runscope\_csv/extract\_data.csv"  
codec =\> 'plain'  
}  
}

filter {  
csv {  
separator =\> ","  
columns =\> ["endpoint","timestamp","code\_status","total\_response\_time","send\_headers\_ms","dial\_ms","send\_body\_ms","wait\_for\_response\_ms","dns\_lookup\_ms","receive\_response\_ms"]  
}

```
    mutate{
            convert => {
            "send_headers_ms" => "float"
            "send_body_ms" => "float"
            "wait_for_response_ms" => "float"
            "dns_lookup_ms" => "float"
            "receive_response_ms" => "float"
            "dial_ms" => "float"
            "total_response_time" => "float"
            }

     }
    mutate {remove_field => ["timestamp"]}

```

}

output {  
elasticsearch {  
hosts =\> "localhost:9200"  
index =\> "runscope"  
document\_id =\> "%{[upc\_code]}  
}  
stdout {}  
}

Please, could you advise in which is failing there?

---

<div class="post-metadata">

**Author:** ![AquaX](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aquax/32/92006_2.png) [@AquaX](https://discuss.elastic.co/u/AquaX)\
**Post date:** [June 25, 2019, 6:34pm UTC](https://discuss.elastic.co/t/logstash-reading-the-file-line-multiple-times/185201/2 "2019-06-25T18:34:57Z")

</div>

Set the number of workers in your pipeline to 1 or if you're running logstash from the command line use the -w 1 parameter

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2019, 6:44pm UTC](https://discuss.elastic.co/t/logstash-reading-the-file-line-multiple-times/185201/3 "2019-07-23T18:44:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
