# Remove first line csv logstash

**URL:** <https://discuss.elastic.co/t/remove-first-line-csv-logstash/212749>\
**Category:** Logstash\
**Created:** [December 21, 2019, 6:08pm UTC](https://discuss.elastic.co/t/remove-first-line-csv-logstash/212749 "2019-12-21T18:08:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![frangolzmil](https://avatars.discourse-cdn.com/v4/letter/f/4af34b/32.png) [@frangolzmil](https://discuss.elastic.co/u/frangolzmil)\
**Post date:** [December 21, 2019, 6:08pm UTC](https://discuss.elastic.co/t/remove-first-line-csv-logstash/212749/1 "2019-12-21T18:08:14Z")

</div>

Hi dudes!

I just wanna remove the header (first line) from my csv files. The first line is containing the column names. After parsing csv file, the visualization on Kibana shows the first line parsed as the column name indicates.

My code:  
input {  
file {  
path =\> "/home/admxxx/xxxx/xxxx/\*.csv"  
start\_position =\> "beginning"  
sincedb\_path =\> "/dev/null"  
}  
}

filter {  
csv {  
columns =\> ["id tweet","date","author","text","app","id user","followers","following","stauses","location","urls","geolocation","name","description","url\_media","type media","quoted","relation","replied\_id","user replied","retweeted\_id","user retweeted","quoted\_id","user quoted","first HT","lang","created\_at","verified","avatar","link"]  
separator =\> ";" #tab  
skip\_header =\> true  
#autodetect\_column\_names =\> true  
#autogenerate\_column\_names =\> true

```
			    }
		      date {
          #match => ["date","yyyy-MM-dd HH:mm:ss"]
          match => ["date","dd/MM/yyyy HH:mm","dd/MM/yyyy H:mm","yyyy-MM-dd HH:mm:ss"]
          timezone => "UTC"
          target => "@timestamp"
		      }
        
        mutate {
          #gsub => ["message","\","'"]
          #remove_field => ["message"]
        }
        ruby {
        code => "
            event.set('index_monitoring_twitter',event.get('path').split('/')[-1].gsub('.csv',''))
        "
        }
        #grok { 
        # match => ["path", "/(?<index_monitoring_twitter>[^/]+).csv" ] 
        # }
	    }        

```

output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
#index =\> "monitorizaciones\_hoarder"  
index =\> "monitorizaciones\_%{index\_monitoring\_twitter}"

}  
stdout{codec =\> rubydebug} #para comprobaciones  
}

Kibana:

 ![imagen](https://us1.discourse-cdn.com/elastic/original/3X/f/2/f24b4648b7bbf6048130f1ef5728748a592635b2.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 21, 2019, 7:19pm UTC](https://discuss.elastic.co/t/remove-first-line-csv-logstash/212749/2 "2019-12-21T19:19:11Z")

</div>

You can check whether the parsed line looks like a header

```
if [id tweet] == "id tweet" { drop {} }

```

after the csv filter, or

```
if [message] =~ /^id tweet;/ { drop {} }

```

before the csv filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 18, 2020, 7:19pm UTC](https://discuss.elastic.co/t/remove-first-line-csv-logstash/212749/3 "2020-01-18T19:19:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
