# Write multiply csv files in logstash output

**URL:** <https://discuss.elastic.co/t/write-multiply-csv-files-in-logstash-output/119482>\
**Category:** Logstash\
**Created:** [February 12, 2018, 2:30pm UTC](https://discuss.elastic.co/t/write-multiply-csv-files-in-logstash-output/119482 "2018-02-12T14:30:14Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![yosi\_ela](https://avatars.discourse-cdn.com/v4/letter/y/779978/32.png) [@yosi\_ela](https://discuss.elastic.co/u/yosi_ela)\
**Post date:** [February 12, 2018, 2:30pm UTC](https://discuss.elastic.co/t/write-multiply-csv-files-in-logstash-output/119482/1 "2018-02-12T14:30:14Z")

</div>

hii ,

i have an input in logstash of beats , and i am writing to csv file in the output .

i want to make a new file of csv in every hour or in every day ?

how i can to define logstash that the current file finish to write close the file and write to other csv file ?

thank you

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [February 12, 2018, 2:36pm UTC](https://discuss.elastic.co/t/write-multiply-csv-files-in-logstash-output/119482/2 "2018-02-12T14:36:16Z")

</div>

The [path option](https://www.elastic.co/guide/en/logstash/current/plugins-outputs-file.html#plugins-outputs-file-path) of the file output plugin allows for variable interpolation (as can be seen in the example), so you can use that to rotate files on a specific interval.

---

<div class="post-metadata">

**Author:** ![yosi\_ela](https://avatars.discourse-cdn.com/v4/letter/y/779978/32.png) [@yosi\_ela](https://discuss.elastic.co/u/yosi_ela)\
**Post date:** [February 12, 2018, 2:43pm UTC](https://discuss.elastic.co/t/write-multiply-csv-files-in-logstash-output/119482/3 "2018-02-12T14:43:50Z")

</div>

ok ,

the question is if in each action of filebeat it will be write other file?  
and from where it tooks the timestamp?

---

<div class="post-metadata">

**Author:** ![paz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paz/32/28003_2.png) [@paz](https://discuss.elastic.co/u/paz)\
**Post date:** [February 12, 2018, 3:02pm UTC](https://discuss.elastic.co/t/write-multiply-csv-files-in-logstash-output/119482/4 "2018-02-12T15:02:53Z")

</div>

I believe Filebeat creates a _@timestamp_ in each event with the time stamp when it read that specific line, so you can use that.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2018, 3:03pm UTC](https://discuss.elastic.co/t/write-multiply-csv-files-in-logstash-output/119482/5 "2018-03-12T15:03:22Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
