# Unable to log CSV

**URL:** <https://discuss.elastic.co/t/unable-to-log-csv/148991>\
**Category:** Logstash\
**Created:** [September 18, 2018, 1:36pm UTC](https://discuss.elastic.co/t/unable-to-log-csv/148991 "2018-09-18T13:36:05Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![AdamD25](https://avatars.discourse-cdn.com/v4/letter/a/7feea3/32.png) [@AdamD25](https://discuss.elastic.co/u/AdamD25)\
**Post date:** [September 18, 2018, 1:36pm UTC](https://discuss.elastic.co/t/unable-to-log-csv/148991/1 "2018-09-18T13:36:05Z")

</div>

Hi,

I'm new to logstash so forgive any obvious mistakes! I've recently installed the ELK stack and have been trying to setup a pipeline to elasticsearch but have hit a wall. My config file (see below) seems to run without a hitch but for some reason my CSV isn't being logged - I've checked the structure of my CSV and edited it recently so there doesn't seem to be a problem there.

input {  
file {  
path =\> "C:\ELK\_Stack\data\test\_data.csv"  
start\_position =\> "beginning"  
sincedb\_path =\> "NUL"  
}  
}  
filter {  
csv {  
separator =\> ","  
columns =\> ["propcode", "prop\_name", "unqid", "PropType", "Portfolio", "asst\_mgr", "OccupStatus", "Occstatus", "TenantName", "ERVunderwr", "LsStart", "LeaseToDate", "NextRRDate", "rentstdate", "Effbrdate", "brknotice", "Tcertexp", "tcertrem", "ContractedRent", "EstimatedRent", "unit\_area"]  
}  
}  
output {  
stdout { codec =\> rubydebug }  
}

I've tried using the --debug mode but haven't spotted anything useful, I've put the output on pastebin:

[https://pastebin.com/bpgfLzBV](https://pastebin.com/bpgfLzBV)

Any help would be hugely appreciate!

Kind regards,

Adam

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [September 24, 2018, 7:53pm UTC](https://discuss.elastic.co/t/unable-to-log-csv/148991/2 "2018-09-24T19:53:50Z")

</div>

This behaviour is due to the strict way that the "tailing" concept has been interpreted, like the unix `tail -f` command.  
If a file is present when Logstash starts, then reading starts from the end, i.e. only process new content that is seen in the file after LS starts. The start\_position is meant for when a file is "discovered" after LS starts where one can override this tail from the end.

The version of the file input that is shipped with LS 6.4.0 has a ["read" mode](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#_read_mode) - specifically designed for when a file should be read from start to finish (subject to sincedb position tracking, which you opted out of by setting the sincedb\_path to NUL).

Along with read mode is the ability to do some action when the EOF is reached. [The default action is to delete the file](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-file_completed_action), but you can change this to "log" as well as [adding a path to a file](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-file.html#plugins-inputs-file-file_completed_log_path) that will hold the path to each file as it is completed. If using the delete option, make sure that you have a copy of the original.

---

<div class="post-metadata">

**Author:** ![balumurari1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/balumurari1/32/39203_2.png) [@balumurari1](https://discuss.elastic.co/u/balumurari1)\
**Post date:** [October 9, 2018, 11:54am UTC](https://discuss.elastic.co/t/unable-to-log-csv/148991/3 "2018-10-09T11:54:44Z")

</div>

Refer the below link. Hope this helps you,  
[https://discuss.elastic.co/t/load-csv-file-in-logstash/151319/2](https://discuss.elastic.co/t/load-csv-file-in-logstash/151319/2)

Regards,  
Balu

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 6, 2018, 11:54am UTC](https://discuss.elastic.co/t/unable-to-log-csv/148991/4 "2018-11-06T11:54:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
