# Pipeline: field \[evidence\] not present as part of path \[threatintel.evidence\]

**URL:** <https://discuss.elastic.co/t/pipeline-field-evidence-not-present-as-part-of-path-threatintel-evidence/263008>\
**Category:** Elasticsearch\
**Created:** [February 2, 2021, 3:37pm UTC](https://discuss.elastic.co/t/pipeline-field-evidence-not-present-as-part-of-path-threatintel-evidence/263008 "2021-02-02T15:37:49Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![remote](https://avatars.discourse-cdn.com/v4/letter/r/f08c70/32.png) [@remote](https://discuss.elastic.co/u/remote)\
**Post date:** [February 22, 2021, 6:14pm UTC](https://discuss.elastic.co/t/pipeline-field-evidence-not-present-as-part-of-path-threatintel-evidence/263008/5 "2021-02-22T18:14:10Z")

</div>

I found a workaround by simply adding another semicolon (my column delimiter) at the end of each line in my csv. Worked like a charm.  
Still don't understand why this issue appeared as even trying with a normal string in place of the JSON object in the csv I got the `Illegal character inside unquoted field` error. My other indices work well and have a similar ingest pipeline and didn't require the additional column delimiter.

Other solutions I tried such as [this one](https://discuss.elastic.co/t/csv-input-with-json-in-it/188952) didn't work for me.

---

_[View the full topic](https://discuss.elastic.co/t/pipeline-field-evidence-not-present-as-part-of-path-threatintel-evidence/263008)._
