# LS crashing when trying to read CSV with undefined method \`tv\_sec' error

**URL:** <https://discuss.elastic.co/t/ls-crashing-when-trying-to-read-csv-with-undefined-method-tv-sec-error/67079>\
**Category:** Logstash\
**Created:** [November 24, 2016, 9:26am UTC](https://discuss.elastic.co/t/ls-crashing-when-trying-to-read-csv-with-undefined-method-tv-sec-error/67079 "2016-11-24T09:26:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![fxiger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fxiger/32/12670_2.png) [@fxiger](https://discuss.elastic.co/u/fxiger)\
**Post date:** [November 24, 2016, 9:26am UTC](https://discuss.elastic.co/t/ls-crashing-when-trying-to-read-csv-with-undefined-method-tv-sec-error/67079/1 "2016-11-24T09:26:45Z")

</div>

Hi,

i'm trying to read logifles (written on my own app) with csv format with logstash and output them to an ES index.

**i'm using:**  
logstash 2.4.1  
logstash-filter-csv (2.1.3)  
logstash-input-file (2.2.5)  
logstash-output-elasticsearch (2.7.1)

**my csv-input looks like the following:**  
2016-07-22T12:56:41,774|3|638613696|85807187|0|19,136

**my config:**

> input {  
> file {  
> path =\> "/home/fuxxi/logstash/enriched\_om\_events-\*.log"  
> start\_position =\> "beginning"  
> type =\> "enriched\_event"  
> }  
> }

> filter {  
> if [type] == "enriched\_event" {  
> csv {  
> columns =\> ["@timestamp","service\_id","provisioning\_id","contract\_id","artikelnummer","featurenummer","duration"]  
> separator =\> "|"  
> }  
> }  
> }

> output {  
> if [type] == "enriched\_event" {  
> elasticsearch {  
> action =\> "index"  
> hosts =\> ["localhost"]  
> index =\> "om\_enriched-%{+YYYY.MM.dd}"  
> }  
> stdout {  
> codec =\> rubydebug  
> }  
> }  
> }

but, after startup, i get this error:

> /opt/logstash/bin/logstash -f /etc/logstash/conf.d/om\_elastic.conf  
> Settings: Default pipeline workers: 8  
> Pipeline main started  
> NoMethodError: undefined method `tv\_sec' for "2016-07-23T12:47:23,315":String  
> evaluate at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-event-2.4.1-java/lib/logstash/string\_interpolation.rb:153  
> evaluate at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-event-2.4.1-java/lib/logstash/string\_interpolation.rb:90  
> collect at org/jruby/RubyArray.java:2409  
> evaluate at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-event-2.4.1-java/lib/logstash/string\_interpolation.rb:90  
> evaluate at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-event-2.4.1-java/lib/logstash/string\_interpolation.rb:27  
> sprintf at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-event-2.4.1-java/lib/logstash/event.rb:202  
> event\_action\_params at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:131  
> event\_action\_tuple at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:35  
> multi\_receive at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:29  
> map at org/jruby/RubyArray.java:2414  
> multi\_receive at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:29  
> each\_slice at org/jruby/RubyArray.java:1653  
> multi\_receive at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-output-elasticsearch-2.7.1-java/lib/logstash/outputs/elasticsearch/common.rb:28  
> worker\_multi\_receive at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.1-java/lib/logstash/output\_delegator.rb:130  
> multi\_receive at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.1-java/lib/logstash/output\_delegator.rb:114  
> output\_batch at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.1-java/lib/logstash/pipeline.rb:301  
> each at org/jruby/RubyHash.java:1342  
> output\_batch at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.1-java/lib/logstash/pipeline.rb:301  
> worker\_loop at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.1-java/lib/logstash/pipeline.rb:232  
> start\_workers at /opt/logstash/vendor/bundle/jruby/1.9/gems/logstash-core-2.4.1-java/lib/logstash/pipeline.rb:201

i tried, to find a solution and better understanding while googling for this error, but i'm stuck and not able to figure out, how to solve ☹

---

<div class="post-metadata">

**Author:** ![fxiger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fxiger/32/12670_2.png) [@fxiger](https://discuss.elastic.co/u/fxiger)\
**Post date:** [November 25, 2016, 1:51pm UTC](https://discuss.elastic.co/t/ls-crashing-when-trying-to-read-csv-with-undefined-method-tv-sec-error/67079/2 "2016-11-25T13:51:47Z")

</div>

When i change the filter config like this:

> ```
> if [type] == "enriched_event" {
> csv {
> columns => ["timestamp","service_id","provisioning_id","contract_id","artikelnummer","featurenummer","duration"]
> separator => "|"
> }
> }
> 
> ```

( **removing the @ in timestamp** ) i'm able to forward my csv log to ES but a new @timestamp field is created with the current date/time. In Kibana, i can still use my own timestamp field. But i'm still lacking in knowledge regarding the @timestamp field ☹

---

<div class="post-metadata">

**Author:** ![rivaanbechan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rivaanbechan/32/12900_2.png) [@rivaanbechan](https://discuss.elastic.co/u/rivaanbechan)\
**Post date:** [November 25, 2016, 2:24pm UTC](https://discuss.elastic.co/t/ls-crashing-when-trying-to-read-csv-with-undefined-method-tv-sec-error/67079/3 "2016-11-25T14:24:51Z")

</div>

I'm no expert but **@timestamp** is an internal field, so your field is conflicting with it.

I would think you need to name the column **timestamp** as you've done. Then parse the date through the **date filter** after the **csv filter**.

```
date {
  match => ["timestamp" , "YYYY-MM-ddHH:mm:ss,SSS"]
  target => "@timestamp"   
}

```

I haven't tested this, might have to go lookup the match pattern syntax. Although this should put you on the right track 🙂

Thereafter remove the **timestamp** field.

```
mutate {
  remove_field => ["timestamp"]
}

```

Hope this helps 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 29, 2016, 9:24pm UTC](https://discuss.elastic.co/t/ls-crashing-when-trying-to-read-csv-with-undefined-method-tv-sec-error/67079/4 "2016-11-29T21:24:26Z")

</div>

Yes, @rivaanbechan is right, a date filter is needed. I suggest the `remove_field` option is added to the date filter instead.

```nohighlight
date {
  match => ["timestamp" , "YYYY-MM-ddHH:mm:ss,SSS"]
  remove_field => ["timestamp"]
}

```

---

<div class="post-metadata">

**Author:** ![fxiger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fxiger/32/12670_2.png) [@fxiger](https://discuss.elastic.co/u/fxiger)\
**Post date:** [December 1, 2016, 11:43am UTC](https://discuss.elastic.co/t/ls-crashing-when-trying-to-read-csv-with-undefined-method-tv-sec-error/67079/5 "2016-12-01T11:43:51Z")

</div>

Thanks @magnusbaeck and @rivaanbechan, your tipps were helpful!  
I was able to solve my problem by using match, target and remove as suggested.

I really appreciated your advice!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 29, 2016, 11:43am UTC](https://discuss.elastic.co/t/ls-crashing-when-trying-to-read-csv-with-undefined-method-tv-sec-error/67079/6 "2016-12-29T11:43:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
