# Using Csv filter on a Split value

**URL:** <https://discuss.elastic.co/t/using-csv-filter-on-a-split-value/86094>\
**Category:** Logstash\
**Created:** [May 17, 2017, 11:50am UTC](https://discuss.elastic.co/t/using-csv-filter-on-a-split-value/86094 "2017-05-17T11:50:03Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![sahar\_q](https://avatars.discourse-cdn.com/v4/letter/s/dbc845/32.png) [@sahar\_q](https://discuss.elastic.co/u/sahar_q)\
**Post date:** [May 17, 2017, 11:50am UTC](https://discuss.elastic.co/t/using-csv-filter-on-a-split-value/86094/1 "2017-05-17T11:50:03Z")

</div>

I used mutate and split in order to split the data im getting, i want to pass each of the value i spilted on the csv filter but i dont get how to do it, any help?

this is my current config:

> filter{  
> mutate {  
> split =\> {"message" =\> "|"}  
> }  
> csv {  
> columns =\> [  
> "interface",  
> "ip address",  
> "physical address",  
> "type"  
> ]   
> separator =\> ","   
> }  
> }

this is part of the input data:

> "192.168.56.1","225.0.0.251","ff-ff-ff-ff-ff-ff","static"|  
> "192.168.56.1","225.0.0.252","01-00-5e-00-00-16","static"|  
> "192.168.56.1","225.0.0.253","01-00-5e-00-00-fb","static"|  
> "192.168.56.1","225.0.0.254","01-00-5e-00-00-fc","static"|  
> "192.168.56.1","225.0.0.255","01-00-5e-00-00-fd","static"|

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 21, 2017, 12:01am UTC](https://discuss.elastic.co/t/using-csv-filter-on-a-split-value/86094/2 "2017-05-21T00:01:07Z")

</div>

Please don't post multiple threads on the same question 🙂

> [@Determine when to stop capturing event and start another one](https://discuss.elastic.co/t/determine-when-to-stop-capturing-event-and-start-another-one/86078):
>
> Hi guys, say im sending an data to log stahs through http, the data is separated in commas and each line represent and single event (that i want it to be independent as a document) Data for example: "192.168.0.1","255.255.255.245","01-00-5e-40-98-8f","static"| "192.168.0.1","255.255.255.250","01-00-5e-7f-ff-fa","static"| "192.168.0.1","255.255.255.255","ff-ff-ff-ff-ff-ff","static"| i used csv filter like so : csv { columns =\> [ "interface", "ip address", "physical address", "type" …

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [May 21, 2017, 12:01am UTC](https://discuss.elastic.co/t/using-csv-filter-on-a-split-value/86094/3 "2017-05-21T00:01:10Z")

</div>


