# Use information of first line in the rest of the file

**URL:** <https://discuss.elastic.co/t/use-information-of-first-line-in-the-rest-of-the-file/83115>\
**Category:** Logstash\
**Created:** [April 20, 2017, 9:04pm UTC](https://discuss.elastic.co/t/use-information-of-first-line-in-the-rest-of-the-file/83115 "2017-04-20T21:04:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![thix](https://avatars.discourse-cdn.com/v4/letter/t/6a8cbe/32.png) [@thix](https://discuss.elastic.co/u/thix)\
**Post date:** [April 20, 2017, 9:04pm UTC](https://discuss.elastic.co/t/use-information-of-first-line-in-the-rest-of-the-file/83115/1 "2017-04-20T21:04:25Z")

</div>

Hi, everyone.

First of all I'd like to do two things:

1. Apologize to all about my bad English.

2. Congratulate you about this amazing project (ELK).

My case is....

I have millions of text files with the following structure.

One "header" line, one "column header" line, multiple "data" lines and one "trailer" line.

The information i need to send to ES is the "data" lines, but the identification of the file is on the first line.  
So, for each request (data line) I need to append the identification of the file before upload it to ES.

What is the proper way to do that?

I'm able to parse the text file using the 'csv' filter. But I don't know how to use data from the first line on other lines.  
Maybe I can declare a variable in ruby when reading the first line and use it on the rest of the file?  
How is that approach affected by multiple workers?

Some more info:

Example of a file:

```
v1234	10373	17/03/17 23:35:43	M
DATE	DATA1	DATA2	DATA3
26/10/16 06:40	1	1 (ok)	05	
15/03/17 21:07	1	1 (ok)	00	
2	89067EC2711277ABF279DC5B743BD9D250F78495	23296	1100

```

The above example is a file with one header, one column header, two data lines and one trailer.

I need to send both data lines to ES with the file identifier (10373).

Can anyone help me?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![thix](https://avatars.discourse-cdn.com/v4/letter/t/6a8cbe/32.png) [@thix](https://discuss.elastic.co/u/thix)\
**Post date:** [April 25, 2017, 5:41pm UTC](https://discuss.elastic.co/t/use-information-of-first-line-in-the-rest-of-the-file/83115/2 "2017-04-25T17:41:45Z")

</div>

This is what I`'m trying:

```
filter {
        csv {
               columns => ["data1", "data2", "data3", "data4"]
               separator => "	"
        }
	if ([data1] == "v1234") {
		ruby{
			init => "@@userId = ''"
			code => "@@userId = event.get('[data2]')"
		}
		drop { }
	}
	ruby{
		code => "event.set('usuario', @@userId)"
	}
}

```

But the value of "usuario" is always nil

---

<div class="post-metadata">

**Author:** ![thix](https://avatars.discourse-cdn.com/v4/letter/t/6a8cbe/32.png) [@thix](https://discuss.elastic.co/u/thix)\
**Post date:** [April 26, 2017, 3:25pm UTC](https://discuss.elastic.co/t/use-information-of-first-line-in-the-rest-of-the-file/83115/3 "2017-04-26T15:25:22Z")

</div>

Solved my own problem.

I was removing "data2" in the CSV filter.

I'll keep it here for someone with the same problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 24, 2017, 3:35pm UTC](https://discuss.elastic.co/t/use-information-of-first-line-in-the-rest-of-the-file/83115/4 "2017-05-24T15:35:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
