# Why all csv columns are saved inside message field

**URL:** <https://discuss.elastic.co/t/why-all-csv-columns-are-saved-inside-message-field/169598>\
**Category:** Logstash\
**Created:** [February 22, 2019, 2:53pm UTC](https://discuss.elastic.co/t/why-all-csv-columns-are-saved-inside-message-field/169598 "2019-02-22T14:53:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![user\_csv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/user_csv/32/41253_2.png) [@user\_csv](https://discuss.elastic.co/u/user_csv)\
**Post date:** [February 22, 2019, 2:53pm UTC](https://discuss.elastic.co/t/why-all-csv-columns-are-saved-inside-message-field/169598/1 "2019-02-22T14:53:46Z")

</div>

Hi,  
I'm trying to load a CSV file into Elasticsearch using Logstash, but the problem is all the csv columns are saved inside message fiels heres the config file:  
input {  
file {  
path =\> "C:/Users/zya/Documents/ELK\_Stack/logstash-6.6.0/logstash-6.6.0/config/statistique\_logs\_bledina\_prod.csv"  
start\_position =\> "beginning"  
sincedb\_path =\> "null"  
}  
}  
filter {  
csv {  
separator =\> ","  
columns =\> ["Date","Serveur","......"]

}  
}  
output {  
elasticsearch {  
hosts =\> "[http://localhost:9200](http://localhost:9200)"  
index =\> "bledina185"  
document\_type =\> "bledinaio72"  
}  
stdout {}  
}

heres a pic the data in Elasticsearch :

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/1/b1a6934b83a2b78ce8906dfa230e29418f2840f1.png)

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 22, 2019, 2:56pm UTC](https://discuss.elastic.co/t/why-all-csv-columns-are-saved-inside-message-field/169598/2 "2019-02-22T14:56:50Z")

</div>

You have specified `,` as separator in your CSV filter but the data seems to be separated by `;`.

---

<div class="post-metadata">

**Author:** ![user\_csv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/user_csv/32/41253_2.png) [@user\_csv](https://discuss.elastic.co/u/user_csv)\
**Post date:** [February 22, 2019, 3:10pm UTC](https://discuss.elastic.co/t/why-all-csv-columns-are-saved-inside-message-field/169598/3 "2019-02-22T15:10:17Z")

</div>

thanks for your answer ser, I tried to change the separator, but I always get the same probleme, here a picture of the csv file

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/b/d/bd937f3a750e1bc12676b52b8fb080b672b43b67.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 22, 2019, 3:11pm UTC](https://discuss.elastic.co/t/why-all-csv-columns-are-saved-inside-message-field/169598/4 "2019-02-22T15:11:57Z")

</div>

> [@user\_csv](#):
>
> sincedb\_path =\> "null"

In addition to changing the separator to be ; you should change that to be NUL.

---

<div class="post-metadata">

**Author:** ![user\_csv](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/user_csv/32/41253_2.png) [@user\_csv](https://discuss.elastic.co/u/user_csv)\
**Post date:** [February 22, 2019, 3:16pm UTC](https://discuss.elastic.co/t/why-all-csv-columns-are-saved-inside-message-field/169598/5 "2019-02-22T15:16:43Z")

</div>

its working as expected thank u guys @Badger and @Christian_Dahlqvist for your help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 22, 2019, 3:18pm UTC](https://discuss.elastic.co/t/why-all-csv-columns-are-saved-inside-message-field/169598/6 "2019-03-22T15:18:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
