Logstash CSV输出所有数据在一行,如何配置实现分行输出?
Let's work through this issue step by step—this is a common pitfall with Logstash's CSV plugin, but it's straightforward to resolve once you know where to focus!
If all your output ends up crammed into one line, the root cause is almost always that Logstash isn't splitting your input CSV into separate, individual events. The row_sep setting in your output only works if each row from your input is being processed as its own event. Here's what you need to adjust:
1. Make Sure Your Input Splits Rows into Events
First, confirm your input configuration is correctly parsing each CSV row as a distinct event. Use the line codec to split the input file by newlines, and pair it with the csv filter to parse each row into fields:
input { file { path => "/path/to/your/input.csv" start_position => "beginning" # Critical if you're reprocessing the file codec => "line" # This splits the input into individual lines/events } } filter { csv { columns => ["Date", "Open"] # Match the exact columns from your input CSV separator => "," } }
2. Adjust row_sep to Match Your Operating System
Your current row_sep => "\r\n" is Windows-style line endings, but if you're on a Unix/Linux/macOS system, the default line ending is "\n". Switching to the correct line ending for your OS often fixes the single-line output issue:
output { csv { path => "/tmp/BCHARTS-MTGOXUSD-output2.csv" fields => ["Date","Open"] csv_options => { "col_sep" => "," "row_sep" => "\n" # Use this for Unix/Linux/macOS; keep "\r\n" for Windows } } }
3. Verify Event Processing (Debug Step)
If the above changes don't work, check Logstash's logs (usually in /var/log/logstash/ or your console if running in foreground) for CSV parsing errors. You can also add a temporary stdout output to confirm each row is being processed as a separate event:
output { stdout { codec => rubydebug } # This will print each event to your console for inspection csv { path => "/tmp/BCHARTS-MTGOXUSD-output2.csv" fields => ["Date","Open"] csv_options => { "col_sep" => "," "row_sep" => "\n" } } }
If the rubydebug output shows multiple rows merged into one event, your input file might use non-standard line endings (like "\r" instead of "\n"). On Unix systems, use cat -A to inspect the file's line endings and adjust your input codec accordingly.
内容的提问来源于stack exchange,提问作者Pablo Ezequiel Inchausti

