# Reading CSV and applying indexing from logstash taking too much time

**URL:** <https://discuss.elastic.co/t/reading-csv-and-applying-indexing-from-logstash-taking-too-much-time/171684>\
**Category:** Logstash\
**Created:** [March 11, 2019, 7:23am UTC](https://discuss.elastic.co/t/reading-csv-and-applying-indexing-from-logstash-taking-too-much-time/171684 "2019-03-11T07:23:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pk96375](https://avatars.discourse-cdn.com/v4/letter/p/48db29/32.png) [@pk96375](https://discuss.elastic.co/u/pk96375)\
**Post date:** [March 11, 2019, 7:23am UTC](https://discuss.elastic.co/t/reading-csv-and-applying-indexing-from-logstash-taking-too-much-time/171684/1 "2019-03-11T07:23:13Z")

</div>

I am using below configuration for indexing using logstash

# File -\> Logstash -\> Elasticsearch pipeline.

input {  
file {  
path =\> "C:/Users/temp/100\_CC\_Records.csv"  
start\_position=\>"beginning"  
}  
}

filter {  
csv{  
separator=\>","  
columns=\>["card\_holder\_name"]  
}  
}

output {  
elasticsearch{  
hosts=\>"localhost"  
index=\>"list"  
document\_type=\>"check"  
}  
stdout{}  
}

Indexing is taking too much time.  
Please help to resolve this issue.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 11, 2019, 8:22am UTC](https://discuss.elastic.co/t/reading-csv-and-applying-indexing-from-logstash-taking-too-much-time/171684/2 "2019-03-11T08:22:32Z")

</div>

I think you will need to provide some additional information. What does your data look like? What is the hardware this is running on? How are the components configured? What indexing throughput are you actually seeing?

---

<div class="post-metadata">

**Author:** ![pk96375](https://avatars.discourse-cdn.com/v4/letter/p/48db29/32.png) [@pk96375](https://discuss.elastic.co/u/pk96375)\
**Post date:** [March 11, 2019, 9:26am UTC](https://discuss.elastic.co/t/reading-csv-and-applying-indexing-from-logstash-taking-too-much-time/171684/3 "2019-03-11T09:26:04Z")

</div>

card\_type\_code,card\_type\_name,issue\_bank,card\_number,card\_holder\_name,cvv\_cvv2,issue\_date,expiry\_date,bill\_date,card\_pin,credit\_limit  
DS,Discover,Discover,6.4802E+15,Brenda D Peterson,689,Jan-17,Jan-22,4,1998,22700  
DC,Diners Club International,Diners Club,3.02952E+13,Dawn U Reese,70,Dec-15,Dec-16,11,3915,12700

Like above there are hundred records.

System Configuration :  
Host : localhost  
RAM : 8 GB  
OS : Windows 7 Enterprise 64-bit  
Java Version : 1.8.0\_201

[2019-03-11T16:07:40,231][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified  
[2019-03-11T16:07:41,030][INFO][logstash.runner] Starting Logstash {"logstash.version"=\>"6.6.0"}  
[2019-03-11T16:11:21,193][WARN][logstash.outputs.elasticsearch] You are using a deprecated config setting "document\_type" set in elasticsearch. Deprecated settings will continue to work, but are scheduled for removal from logstash in the future. Document types are being deprecated in Elasticsearch 6.0, and removed entirely in 7.0. You should avoid this feature If you have any questions about this, please visit the #logstash channel on freenode irc. {:name=\>"document\_type", :plugin=\>\<LogStash::Outputs::ElasticSearch index=\>"wclist", id=\>"410d4d4cfdcb001aef1266eb868fe1f1b1bc239a051b0bcca06ecaaab2d5c4e0", hosts=\>[[//localhost](https://localhost)], document\_type=\>"wccheck", enable\_metric=\>true, codec=\>\<LogStash::Codecs::Plain id=\>"plain\_ac9e8779-6478-4a26-aa68-c2bae98e5faa", enable\_metric=\>true, charset=\>"UTF-8"\>, workers=\>1, manage\_template=\>true, template\_name=\>"logstash", template\_overwrite=\>false, doc\_as\_upsert=\>false, script\_type=\>"inline", script\_lang=\>"painless", script\_var\_name=\>"event", scripted\_upsert=\>false, retry\_initial\_interval=\>2, retry\_max\_interval=\>64, retry\_on\_conflict=\>1, ilm\_enabled=\>false, ilm\_rollover\_alias=\>"logstash", ilm\_pattern=\>"{now/d}-000001", ilm\_policy=\>"logstash-policy", action=\>"index", ssl\_certificate\_verification=\>true, sniffing=\>false, sniffing\_delay=\>5, timeout=\>60, pool\_max=\>1000, pool\_max\_per\_route=\>100, resurrect\_delay=\>5, validate\_after\_inactivity=\>10000, http\_compression=\>false\>}  
[2019-03-11T16:11:46,503][INFO][logstash.pipeline] Starting pipeline {:pipeline\_id=\>"main", "pipeline.workers"=\>2, "pipeline.batch.size"=\>125, "pipeline.batch.delay"=\>50}  
[2019-03-11T16:11:47,537][INFO][logstash.outputs.elasticsearch] Elasticsearch pool URLs updated {:changes=\>{:removed=\>, :added=\>[[http://localhost:9200/](http://localhost:9200/)]}}  
[2019-03-11T16:11:48,134][WARN][logstash.outputs.elasticsearch] Restored connection to ES instance {:url=\>"[http://localhost:9200/](http://localhost:9200/)"}  
[2019-03-11T16:11:48,284][INFO][logstash.outputs.elasticsearch] ES Output version determined {:es\_version=\>6}  
[2019-03-11T16:11:48,320][WARN][logstash.outputs.elasticsearch] Detected a 6.x and above cluster: the `type` event field won't be used to determine the document \_type {:es\_version=\>6}  
[2019-03-11T16:11:48,406][INFO][logstash.outputs.elasticsearch] New Elasticsearch output {:class=\>"LogStash::Outputs::ElasticSearch", :hosts=\>["[//localhost](https://localhost)"]}  
[2019-03-11T16:11:48,431][INFO][logstash.outputs.elasticsearch] Using mapping template from {:path=\>nil}  
[2019-03-11T16:11:48,702][INFO][logstash.outputs.elasticsearch] Attempting to install template {:manage\_template=\>{"template"=\>"logstash-_", "version"=\>60001, "settings"=\>{"index.refresh\_interval"=\>"5s"}, "mappings"=\>{"default"=\>{"dynamic\_templates"=\>[{"message\_field"=\>{"path\_match"=\>"message", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false}}}, {"string\_fields"=\>{"match"=\>"_", "match\_mapping\_type"=\>"string", "mapping"=\>{"type"=\>"text", "norms"=\>false, "fields"=\>{"keyword"=\>{"type"=\>"keyword", "ignore\_above"=\>256}}}}}], "properties"=\>{"@timestamp"=\>{"type"=\>"date"}, "@version"=\>{"type"=\>"keyword"}, "geoip"=\>{"dynamic"=\>true, "properties"=\>{"ip"=\>{"type"=\>"ip"}, "location"=\>{"type"=\>"geo\_point"}, "latitude"=\>{"type"=\>"half\_float"}, "longitude"=\>{"type"=\>"half\_float"}}}}}}}}  
[2019-03-11T16:13:57,238][INFO][logstash.inputs.file] No sincedb\_path set, generating one based on the "path" setting {:sincedb\_path=\>"I:/SBS/ElasticSearch/logstash-6.6.0/data/plugins/inputs/file/.sincedb\_bf6a5f7d7ebd9e36584813bfcd4a1221", :path=\>["C:/Users/pm85549/Desktop/100\_CC\_Records.csv"]}  
[2019-03-11T16:13:57,411][INFO][logstash.pipeline] Pipeline started successfully {:pipeline\_id=\>"main", :thread=\>"#\<Thread:0x701fa52b run\>"}  
[2019-03-11T16:13:57,560][INFO][logstash.agent] Pipelines running {:count=\>1, :running\_pipelines=\>[:main], :non\_running\_pipelines=\>}  
[2019-03-11T16:13:57,616][INFO][filewatch.observingtail] START, creating Discoverer, Watch with file and sincedb collections  
[2019-03-11T16:14:40,495][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=\>9600}

Nothing happens after this log.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 11, 2019, 9:55am UTC](https://discuss.elastic.co/t/reading-csv-and-applying-indexing-from-logstash-taking-too-much-time/171684/4 "2019-03-11T09:55:44Z")

</div>

I suspect this may be due to the sincedb file preventing file to be reread. Have a look at the `sincedb_path` configuration parameter in the documentation and then set it to `"NUL"` to disable it in the file input specification.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 8, 2019, 9:55am UTC](https://discuss.elastic.co/t/reading-csv-and-applying-indexing-from-logstash-taking-too-much-time/171684/5 "2019-04-08T09:55:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
