# Translate csv failed - caused by a missing field

**URL:** <https://discuss.elastic.co/t/translate-csv-failed-caused-by-a-missing-field/218522>\
**Category:** Logstash\
**Created:** [February 10, 2020, 6:39am UTC](https://discuss.elastic.co/t/translate-csv-failed-caused-by-a-missing-field/218522 "2020-02-10T06:39:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [February 10, 2020, 6:39am UTC](https://discuss.elastic.co/t/translate-csv-failed-caused-by-a-missing-field/218522/1 "2020-02-10T06:39:56Z")

</div>

Logstash 7.3.1

I read from csv:

> columns =\> ["field1","field2","field3","field4","field5","field6","field7","field8","field9","field10","field11","field12","CustomID","field13","field14"]

Then I want to enrich my docs by using translate on field CustomID:

```
translate {
field => "CustomID"
dictionary_path => "C:/path/path/path/translate.csv"
refresh_interval => 500
destination => "MAPPING"
fallback => "nan"
}
dissect {
mapping => {
"MAPPING" => "%{field1},%{field2},%{field3},%{field4},%{field5},%{field6},%{field7}"
}
}

```

My translate.csv file looks this:

> "CustomID","field1,field2,field3,field4,field5,field6,field7"

Now in Logstash log I found following entries:

```
[2020-02-10T06:39:50,719][WARN][org.logstash.dissect.Dissector] Dissector mapping, pattern not found 
{"field"=>"MAPPING", "pattern"=>"%{field1},%{field2},%{field3},%{field4},%{field5},%{field6},%{field7}", 
"event"=>{"afield1"=>"value", "host"=>"mymachine", "afield2"=>"value", "MAPPING"=>"nan", "afield3"=>"value", and few more fields...
"@version"=>"1", "message"=>"value1;value2;value3;value4;value5;value6;value7;value8;;value10,value11;value12;value13;value14;value15;value16\r", "@timestamp"=>2020-02-10T05:39:47.312Z, "CustomID"=>"123456", and so on ==> "tags"=>["_dissectfailure"]

```

Why the mapping failed "MAPPING"=\>"nan" just because a field of my **message** have no entry:  
"message"=\> value8;;value10 (value9 isnt there)

But the "CustomID"=\>"123456" is there and the mapping just should enrich my data by LookUp the CustomID not on field9.

Why this happens, that makes no sense to me.  
Do the translater expect the existing of all fields and values in the message even if they are  
"outside of the KEY field" and have nothing to do with the translate process itself?

Thanks for any help here because this looks like a major issue for me!

Brgds

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 10, 2020, 3:03pm UTC](https://discuss.elastic.co/t/translate-csv-failed-caused-by-a-missing-field/218522/2 "2020-02-10T15:03:51Z")

</div>

> [@Datakids](#):
>
> Why this happens, that makes no sense to me.

You have set fallback to "nan". The translate filter failed to find the value of CustomId in the dictionary, so it used the fallback. The dissect filter is unable to parse the fallback.

---

<div class="post-metadata">

**Author:** ![Datakids](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/datakids/32/39622_2.png) [@Datakids](https://discuss.elastic.co/u/Datakids)\
**Post date:** [February 11, 2020, 3:51pm UTC](https://discuss.elastic.co/t/translate-csv-failed-caused-by-a-missing-field/218522/3 "2020-02-11T15:51:05Z")

</div>

Hi Badger,  
thanks for your thoughts.  
Ok, that means I need a second dissect to parse the fallback?  
However I cant believe the CustomID isnt there so I will check this  
manualy, puhhh...  
Regards

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2020, 3:51pm UTC](https://discuss.elastic.co/t/translate-csv-failed-caused-by-a-missing-field/218522/4 "2020-03-10T15:51:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
