# Merge data and metadata csv file in logstash

**URL:** <https://discuss.elastic.co/t/merge-data-and-metadata-csv-file-in-logstash/295815>\
**Category:** Logstash\
**Created:** [January 31, 2022, 10:08am UTC](https://discuss.elastic.co/t/merge-data-and-metadata-csv-file-in-logstash/295815 "2022-01-31T10:08:00Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 31, 2022, 6:46pm UTC](https://discuss.elastic.co/t/merge-data-and-metadata-csv-file-in-logstash/295815/2 "2022-01-31T18:46:19Z")

</div>

When a translate filter [loads a csv](https://github.com/logstash-plugins/logstash-filter-translate/blob/e3670bb3137437ad05a90036a90b4711a67e04ea/lib/logstash/filters/dictionary/csv_file.rb#L21) it only uses the first two columns.

[Treatment] is incorrect because in your dissect filter you are mapping [message], when you probably meant to map [@metadata][match].

If you change the metadata csv to be

> **Sample** ,Treatment,Code  
> S4444003,T\_7896\_D3;G10  
> S4444004,T\_4516\_D0t1h;G01

using semi-colon as the separator for the second and third columns you could use

```
dissect { mapping => { "[@metadata][match]" => "%{Treatment};%{Code}" } }

```

[This](https://discuss.elastic.co/t/translate-filter-plugin/167971) thread discusses other options.

---

_[View the full topic](https://discuss.elastic.co/t/merge-data-and-metadata-csv-file-in-logstash/295815)._
