# Splitting csv files send to elasticsearch via logstash http input

**URL:** <https://discuss.elastic.co/t/splitting-csv-files-send-to-elasticsearch-via-logstash-http-input/278144>\
**Category:** Logstash\
**Created:** [July 8, 2021, 7:19am UTC](https://discuss.elastic.co/t/splitting-csv-files-send-to-elasticsearch-via-logstash-http-input/278144 "2021-07-08T07:19:45Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![reynavan](https://avatars.discourse-cdn.com/v4/letter/r/a3d4f5/32.png) [@reynavan](https://discuss.elastic.co/u/reynavan)\
**Post date:** [July 8, 2021, 7:19am UTC](https://discuss.elastic.co/t/splitting-csv-files-send-to-elasticsearch-via-logstash-http-input/278144/1 "2021-07-08T07:19:45Z")

</div>

Hello!  
I am new to ELK stack and I'm looking for some advice. I have 3 different types of csv's files which are generated every day, I'm sending them to IP address where logstash is configured, than i want to visualize data from those files in kibana. When i was trying things locally i was using `file` input, where every line from files was treated as new event and than i was using "if else" to apply proper csv filter to file based on number of columns and everything worked as i wanted. Now when i send those files to IP address, http input process files as one event and nothing works. I tried to use `split` filter but couldn't get it to work 😑 Should i tried different approach, or I am forgetting about something obvious? here is my config file( i left split filter empty now as I could not get it to work but i suspect i need to use it):

```auto
input {
		http{
		}
}
filter{
 split{}
 ruby { code => 'event.set("[@metadata][columns]", 1 + event.get("message").count(","))' }
	if [@metadata][columns] == 7{
	csv{
		separator => ","
		columns => ["Class","Asset Name","Issue","Value","Severity","Path", "Date"]
		}
	mutate{
	add_tag => "assets"
	}	
 }else if [@metadata][columns] == 8{
	csv { 
		separator => ","
		columns => ["Time (ms)","Frame (ms)","GT (ms)","RT (ms)","GPU (ms)","DynRes","Context","Date"] 
		}
		mutate{
		add_tag => "fps_profiling"
		convert => {
		"Time (ms)" => "float"
		"Frame (ms)" => "float"
		"GT (ms)" => "float"
		"RT (ms)" => "float"
		"GPU (ms)" => "float"
		"DynRes" => "float"
		"Context" => "integer"
		}
		}
 } else if [@metadata][columns] == 9{
        csv { 
		separator => ","
		columns => ["Percentile","Frame (ms)","GT (ms)","RT (ms)","GPU (ms)","DynRes","Context","Date"]
		}
		mutate{
		add_tag => "fps_profiling" 
		convert => {
		"Percentile" => "float"
		"Frame (ms)" => "float"
		"GT (ms)" => "float"
		"GPU (ms)" => "float"
		"DynRes" => "float"
		"Context" => "integer"
		}
		}
}

date {
    match => ["Date", "ISO8601", "YYYY-MM-dd HH:mm:ss", "YYYY-MM-dd HH:mm:ss.ZZZ"]
	target => "Date"    
    }
	}

output {
	stdout {codec => rubydebug}
	if "fps_profiling" in [tags]{
	elasticsearch{
		hosts => ["localhost:9200"]
		index => "performance_tests"
	}
	}else {
	elasticsearch{
	hosts => ["localhost:9200"]
	index => "assets_validation"
	}
	}

}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 5, 2021, 7:20am UTC](https://discuss.elastic.co/t/splitting-csv-files-send-to-elasticsearch-via-logstash-http-input/278144/2 "2021-08-05T07:20:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
