# Add field from csv to event log send by logstash

**URL:** <https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677>\
**Category:** Logstash\
**Created:** [March 7, 2017, 2:13pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677 "2017-03-07T14:13:44Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 7, 2017, 2:13pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/1 "2017-03-07T14:13:44Z")

</div>

Hi friends, I have a question about filters.

I have a conf file that works perfectly for sending active directory logs to elasticsearch.  
In my log, I have a field named "event\_data.TargetUserName and it has a registration number.

In my company, all users have a registration number.

So, this is a sample of my csv file :

sAMAccountName;displayName  
C583;jane Doe  
C090;John Doe  
C587;JMichael Jackson

and my logstash conf file (I use logstash 2.4 and elasticsearch 5.2.2)

input {  
kafka {  
zk\_connect =\> "192.168.18.15:2181"  
group\_id =\> "logstash-application"  
topic\_id =\> "ActiveDirectory-Application-Logs"  
reset\_beginning =\> "false"  
consumer\_threads =\> 1  
codec =\> json {}  
}  
output {  
elasticsearch {  
hosts =\> ["192.168.18.15:9200"]  
index =\> "logstash-application-%{+YYYY.MM.dd}"  
}

I don't know which filter using for matching the log field "event\_data.TargetUserName" with the field "sAMAccountName" of my csv file and how to add a field named "userName"

I tried this but without effect :

filter {  
if [event\_data.TargetUserName] == "\*" {  
csv {  
source =\> "/etc/logstash/mutate/ExportADLDS.csv"  
columns =\> ["sAMAccountName","displayName"]  
separator =\> ";"}  
add\_tag =\> ["userName"]  
source =\> "[event\_data][TargetUserName]"   
target =\> "userName"  
add\_field =\> ["{[sAMAccountName]}", "%{[displayName]}"]  
}  
}

A great thanks for your help

Fayce

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2017, 2:22pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/2 "2017-03-07T14:22:18Z")

</div>

So you have events with `[event_data][TargetUserName]` set to e.g. C090 and you want to put "John Doe" into another field? Use the translate filter.

---

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 7, 2017, 2:24pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/3 "2017-03-07T14:24:17Z")

</div>

translate instead of csv ?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2017, 2:25pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/4 "2017-03-07T14:25:00Z")

</div>

Yes.

---

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 7, 2017, 2:38pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/5 "2017-03-07T14:38:57Z")

</div>

Is there a way to make an offline install of that plugin ? There is an error :

./logstash-plugin install logstash-filter-translate

Validating logstash-filter-translate  
Unable to download data from [https://rubygems.org](https://rubygems.org) - Errno::ECONNREFUSED: Connection refused - Connection refused ([https://api.rubygems.org/latest\_specs.4.8.gz](https://api.rubygems.org/latest_specs.4.8.gz))  
ERROR: Installation aborted, verification failed for logstash-filter-translate

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2017, 2:47pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/6 "2017-03-07T14:47:29Z")

</div>

[https://www.elastic.co/guide/en/logstash/current/offline-plugins.html](https://www.elastic.co/guide/en/logstash/current/offline-plugins.html)

---

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 8, 2017, 9:40am UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/7 "2017-03-08T09:40:35Z")

</div>

Hi, I finally succeed to install logstash-filter-translate plugin.

Here is my conf file :

input {  
elasticsearch {  
hosts =\> ["192.168.18.15:9200"]  
index =\> "logstash-security-2017.03.07"  
}  
}

filter {  
mutate {  
add\_field =\> {  
"[userName\_string]" =\> "%{sAMAccountName},%{displayName}"  
}  
}  
translate {  
dictionary\_path =\> "/etc/logstash/mutate/ExportADLDS.csv"  
field =\> "[event\_data.TargetUserName]"   
destination =\> "userName"   
}  
}

output {  
elasticsearch {  
hosts =\> ["192.168.18.15:9200"]  
index =\> "logstash-security-test"  
}  
stdout {}  
}

And the error :

> A plugin had an unrecoverable error. Will restart this plugin.  
> Plugin: \<LogStash::Inputs::Elasticsearch hosts=\>["192.168.18.15:9200"], index=\>"logstash-security-2017.03.07", codec=\>\<LogStash::Codecs::JSON charset=\>"UTF-8"\>, query=\>"{"query": { "match\_all": {} } }", scan=\>true, size=\>1000, scroll=\>"1m", docinfo=\>false, docinfo\_target=\>"@metadata", docinfo\_fields=\>["\_index", "\_type", "\_id"], ssl=\>false\>  
> Error: [400] {"error":{"root\_cause":[{"type":"illegal\_argument\_exception","reason":"No search type for [scan]"}],"type":"illegal\_argument\_exception","reason":"No search type for [scan]"},"status":400} {:level=\>:error}

I am close to find the solution. A little help pleeaaasee 🙂  
Thanks

Fayce

---

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 8, 2017, 1:24pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/8 "2017-03-08T13:24:01Z")

</div>

I tried this with no more success

> input {  
> elasticsearch {  
> hosts =\> ["192.168.18.15:9200"]  
> index =\> "logstash-security-2017.03.07"  
> }  
> }

> filter {  
> translate {  
> dictionary\_path =\> "/etc/logstash/mutate/ExportADLDS.csv"  
> add\_field =\> {"userName\_string%{TargetUserName}" =\> "%{displayName}"}  
> field =\> "event\_data.TargetUserName"  
> destination =\> "event\_data.userName"   
> remove\_field =\> ["@version", "@timestamp"]  
> override =\> true  
> }  
> }

> output {  
> elasticsearch {  
> hosts =\> ["192.168.18.15:9200"]  
> index =\> "logstash-security-2017.03.07"  
> }  
> stdout {}  
> }

---

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 8, 2017, 2:03pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/9 "2017-03-08T14:03:30Z")

</div>

😭 😭 😭

---

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 8, 2017, 4:41pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/10 "2017-03-08T16:41:29Z")

</div>

Last attempt before suicide 🙂

> input{  
> elasticsearch {  
> hosts =\> ["192.168.18.15:9200"]  
> index =\> "logstash-security-2017.03.07"  
> query=\> '{"query": { "match\_all": {"event\_data": {"TargetUserName": true} } }'  
> }  
> }  
> filter{  
> mutate{  
> add\_field =\> {"[@metadata][userName\_string]" =\> "%{event\_data.TargetUserName}"}  
> }  
> translate {  
> dictionary\_path =\> "/etc/logstash/mutate/ExportADLDS.yml"  
> field =\> "[@metadata][userName\_string]"  
> destination =\> "userName"  
> remove\_field =\> ["@version", "@timestamp"]  
> override =\> true  
> }  
> }  
> output {  
> elasticsearch {  
> hosts =\> ["192.168.18.15:9200"]  
> index =\> "logstash-security-2017.03.07"  
> }  
> stdout {}  
> }

And always the same error, don't know where to put expected characher

> fetched an invalid config {:config=\>"input{\r\n elasticsearch {\r\n hosts =\> ["192.168.18.15:9200"]\r\n index =\> "logstash-security-2017.03.07"\r\n query=\>"{"query": { "match\_all": {"event\_data.TargetUserName"} } }"\r\n }\r\n}\r\nfilter{ \r\n mutate{\r\n add\_field =\> {"[@metadata][userName\_string]" =\> "%{event\_data.TargetUserName}"}\r\n }\r\n translate {\r\n dictionary\_path =\> "/etc/logstash/mutate/ExportADLDS.yml"\r\n field =\> "[@metadata][userName\_string]"\r\n destination =\> "userName"\r\n remove\_field =\> ["@version", "@timestamp"]\r\n override =\> true\r\n }\r\n }\r\noutput {\r\n elasticsearch {\r\n hosts =\> ["192.168.18.15:9200"]\r\n index =\> "logstash-security-2017.03.07"\r\n }\r\n stdout {}\r\n}\r\n\n", :reason=\>"Expected one of #, {, } at line 5, column 15 (byte 124) after input{\r\n elasticsearch {\r\n hosts =\> ["192.168.18.15:9200"]\r\n index =\> "logstash-security-2017.03.07"\r\n query=\>"{"", :level=\>:error}

And here is a part of my log stored in ES

> {  
> "\_index": "logstash-security-2017.03.07",  
> "\_type": "wineventlog",  
> "\_id": "AVqq\_VmXc49FTvkI5kKg",  
> "\_score": null,  
> "\_source": {  
> "@timestamp": "2017-03-07T22:59:59.998Z",  
> "beat": {  
> "hostname": "VMDC",  
> "name": "VMDC",  
> "version": "5.1.1"  
> },  
> "computer\_name": "[VMDC.mycompany.fr](http://VMDC.mycompany.fr)",  
> "event\_data": {  
> "LogonType": "3",  
> "TargetDomainName": "DOMAINXXXXX,  
> "TargetLogonId": "0xea4f87c4",  
> "TargetUserName": "M0123345",  
> "TargetUserSid": "S-1-5-21-117609710-1482476501-xxxxxxxx-17782"  
> },  
> "event\_id": 4634,  
> "keywords": [  
> "Audit Success"

I forget the exact mapping of the field event-data.TargetUserName in ES

> {  
> "logstash-security-2017.03.08": {  
> "mappings": {  
> "wineventlog": {  
> "event\_data.TargetUserName": {  
> "full\_name": "event\_data.TargetUserName",  
> "mapping": {  
> "TargetUserName": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "raw": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 9, 2017, 1:39pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/11 "2017-03-09T13:39:06Z")

</div>

You can comment out lines in your configuration to narrow down which line is resulting in the error.

---

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 9, 2017, 3:17pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/12 "2017-03-09T15:17:58Z")

</div>

Thank you Magnus, I tried that too. The difficulty is to set the exact query. Here is the mapping of my field "event\_data.TargetUserName"

GET /logstash-security-2017.03.08/\_mapping/field/event\_data.TargetUserName

> {  
> "logstash-security-2017.03.08": {  
> "mappings": {  
> "wineventlog": {  
> "event\_data.TargetUserName": {  
> "full\_name": "event\_data.TargetUserName",  
> "mapping": {  
> "TargetUserName": {  
> "type": "text",  
> "norms": false,  
> "fields": {  
> "raw": {  
> "type": "keyword",  
> "ignore\_above": 256  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }  
> }

I use that mapping for my query in logstash . Here is my conf file :

> input{  
> elasticsearch {  
> hosts =\> ["192.168.18.15:9200"]  
> index =\> "logstash-security-2017.03.08"  
> codec =\> "json"  
> ssl =\> false  
> docinfo\_fields =\> ["\_index", "\_type", "\_id"]  
> docinfo\_target =\> "@metadata"  
> query =\> "{ "query": {"mappings":{"wineventlog":{"event\_data.TargetUserName":{"full\_name":"event\_data.TargetUserName","mapping":{"TargetUserName":{"type":"text","norms":false,"fields":{"raw":{"type":"keyword","ignore\_above":256}}}}}}}}} }"  
> }  
> }  
> filter{  
> mutate{  
> add\_field =\> {"[@metadata][userName\_string]" =\> "%{event\_data.TargetUserName}"}  
> }  
> translate {  
> dictionary\_path =\> "/etc/logstash/mutate/ExportADLDS.yml"  
> field =\> "event\_data.TargerUserName"  
> destination =\> "userName"  
> remove\_field =\> ["@version", "@timestamp"]  
> override =\> true  
> }  
> }  
> output {  
> elasticsearch {  
> hosts =\> ["192.168.18.15:9200"]  
> manage\_template =\> false  
> index =\> "logstash-security-user-2017.03.08"  
> document\_type =\> "new-type"  
> }  
> stdout {}  
> }

And the error loop :

A plugin had an unrecoverable error. Will restart this plugin.  
Plugin: \<LogStash::Inputs::Elasticsearch hosts=\>["192.168.18.15:9200"], index=\>"logstash-security-2017.03.08", codec=\>\<LogStash::Codecs::JSON charset=\>"UTF-8"\>, ssl=\>false, docinfo\_fields=\>["\_index", "\_type", "\_id"], docinfo\_target=\>"@metadata", query=\>"{ \"query\": {\"mappings\":{\"wineventlog\":{\"event\_data.TargetUserName\":{ \"full\_name\":\"event\_data.TargetUserName\",\"mapping\":{\"TargetUserName\":{\"type\":\"text\",\"norms\":false,\"fields\":{\"raw\":{\"ty pe\":\"keyword\",\"ignore\_above\":256}}}}}}}}} }", scan=\>true, size=\>1000, scroll=\>"1m", docinfo=\>false\>  
Error: [500] {"error":{"root\_cause":[{"type":"json\_parse\_exception","reason":"Unexpected character ('\' (code 92)): was expecting double-quote to start field name\n at [So urce: org.elasticsearch.transport.netty4.ByteBufStreamInput@873f129; line: 1, column: 4]"}],"type":"json\_parse\_exception","reason":"Unexpected character ('\' (code 92)): was expecting double-quote to start field name\n at [Source: org.elasticsearch.transport.netty4.ByteBufStreamInput@873f129; line: 1, column: 4]"},"status":500} {:level=\>:error}

---

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 14, 2017, 12:37pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/13 "2017-03-14T12:37:44Z")

</div>

Hi, here is some news. I upgraded Logstash to 5.2.2 and create new conf file for importing in ES my active directory logs, and installed logstash-filter-translate with an offline package (Thanks Magnus for the link).

I try to add a field to an old index (for the moment) and try to match one existant field (event\_data.TargetUserName) which is registration number of users with my yaml dictionary. If the field is present I want to add a new field with the displayName of the yaml file

yaml file  
sAMAccountName;displayName  
C583: jane Doe  
C090: John Doe  
C587: JMichael Jackson

In a terminal, when I use that command

/opt/logstash/bin# ./logstash -f /etc/logstash/mutate/Add\_userName.conf

I can see that Logstash is parsing my index (all the logs display very fast) and when the parsing is over, my new field isn't here.

What I am missing ??

Here is my conf file for translate old index

> input {  
> elasticsearch {  
> hosts =\> "192.168.18.15:9200"  
> index =\> "logstash-security-2017.03.09"  
> codec =\> "json"  
> query =\> '{"query": {"match\_all": {}}}'  
> }  
> }  
> filter{  
> translate {  
> dictionary\_path =\> "/etc/logstash/mutate/ExportADLDS.yml"  
> field =\> "event\_data.TargetUsername"  
> destination =\> "userName"  
> remove\_field =\> ["@version", "@timestamp"]  
> override =\> true  
> }  
> }  
> output {  
> elasticsearch {  
> hosts =\> "192.168.18.15:9200"  
> manage\_template =\> false  
> index =\> "logstash-security-2017.03.09"  
> }  
> stdout {}  
> }

Thank you dear friends.

Fayce

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2017, 12:39pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/14 "2017-03-14T12:39:16Z")

</div>

Please show an example event, either produced by Logstash's `stdout { codec => rubydebug }` output or the actual Elasticsearch event (copy/paste from the JSON tab in Kibana).

---

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 14, 2017, 12:44pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/15 "2017-03-14T12:44:58Z")

</div>

Thanks Magnus, here is an event with TargetUserName in it:

> {  
> "\_index": "logstash-security-2017.03.09",  
> "\_type": "wineventlog",  
> "\_id": "AVrMXpFlR-S19PVZbRjo",  
> "\_score": null,  
> "\_source": {  
> "computer\_name": "[VMNTXXXXXDC.company.fr](http://VMNTXXXXXDC.company.fr)",  
> "process\_id": 628,  
> "keywords": [  
> "Audit Success"  
> ],  
> "level": "Information",  
> "log\_name": "Security",  
> "record\_number": "4146914779",  
> "event\_data": {  
> "Status": "0x0",  
> "Workstation": "12-U0054",  
> "PackageName": "MICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0",  
> "TargetUserName": "N130042"  
> },  
> "message": "The computer attempted to validate the credentials for an account.\n\nAuthentication Package:\tMICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0\nLogon Account:\tN130042\nSource Workstation:\t12-U0054\nError Code:\t0x0",  
> "opcode": "Info",  
> "type": "wineventlog",  
> "tags": [  
> "ActiveDirectory"  
> ],  
> "thread\_id": 4928,  
> "@timestamp": "2017-03-09T15:56:45.381Z",  
> "event\_id": 4776,  
> "task": "Credential Validation",  
> "provider\_guid": "{54849625-5478-4994-A5BA-3E3B0328C30D}",  
> "beat": {  
> "hostname": "VMNTXXXDC",  
> "name": "VMNTXXXDC",  
> "version": "5.1.1"  
> },  
> "@version": "1",  
> "source\_name": "Microsoft-Windows-Security-Auditing"  
> },  
> "fields": {  
> "@timestamp": [  
> 1489075005381  
> ]  
> },  
> "sort": [  
> 1489075005381  
> ]  
> }

---

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 14, 2017, 12:46pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/16 "2017-03-14T12:46:27Z")

</div>

Another one, a little bit different

> {  
> "\_index": "logstash-security-2017.03.09",  
> "\_type": "wineventlog",  
> "\_id": "AVrMbOuUR-S19PVZcaDq",  
> "\_score": null,  
> "\_source": {  
> "computer\_name": "[VMNTXXXDC.company.fr](http://VMNTXXXDC.company.fr)",  
> "process\_id": 628,  
> "keywords": [  
> "Audit Success"  
> ],  
> "level": "Information",  
> "log\_name": "Security",  
> "record\_number": "4146914776",  
> "event\_data": {  
> "TargetLogonId": "0xe8f3149a",  
> "LogonType": "3",  
> "TargetUserName": "N129244",  
> "TargetDomainName": "COMPANY",  
> "TargetUserSid": "S-1-5-21-117609710-1482476501-1801674531-60335"  
> },  
> "message": "An account was logged off.\n\nSubject:\n\tSecurity ID:\t\tS-1-5-21-117609710-1482476501-1801674531-60335\n\tAccount Name:\t\tN129244\n\tAccount Domain:\t\tINTRANICE\n\tLogon ID:\t\t0xE8F3149A\n\nLogon Type:\t\t\t3\n\nThis event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.",  
> "opcode": "Info",  
> "type": "wineventlog",  
> "tags": [  
> "ActiveDirectory"  
> ],  
> "thread\_id": 1360,  
> "@timestamp": "2017-03-09T15:56:45.253Z",  
> "event\_id": 4634,  
> "task": "Logoff",  
> "provider\_guid": "{54849625-5478-4994-A5BA-3E3B0328C30D}",  
> "beat": {  
> "hostname": "VMNTXXXDC",  
> "name": "VMNTXXXDC",  
> "version": "5.1.1"  
> },  
> "@version": "1",  
> "source\_name": "Microsoft-Windows-Security-Auditing"  
> },  
> "fields": {  
> "@timestamp": [  
> 1489075005253  
> ]  
> },  
> "sort": [  
> 1489075005253  
> ]  
> }

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2017, 12:50pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/17 "2017-03-14T12:50:30Z")

</div>

You have no `Event.TargetUserName` field, but you have an `Event` field which has a `TargetUserName` subfield. The correct syntax for addressing that field is `[Event][TargetUserName]`. See [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references).

---

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 14, 2017, 1:03pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/18 "2017-03-14T13:03:50Z")

</div>

It create a new event with tag "\_grokparsefailure" for each event present in the index

{  
"\_index": "logstash-security-2017.03.09",  
"\_type": "wineventlog",  
"\_id": "AVrMwF1CR-S19PVZhdBp",  
"\_score": null,  
"\_source": {  
"computer\_name": "[VMNT656DC.intranice.ville-nice.fr](http://VMNT656DC.intranice.ville-nice.fr)",  
"process\_id": 628,  
"keywords": [  
"Audit Success"  
],  
"level": "Information",  
"log\_name": "Security",  
"record\_number": "4146914779",  
"event\_data": {  
"Status": "0x0",  
"Workstation": "12-U0054",  
"PackageName": "MICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0",  
"TargetUserName": "N130042"  
},  
"message": "The computer attempted to validate the credentials for an account.\n\nAuthentication Package:\tMICROSOFT\_AUTHENTICATION\_PACKAGE\_V1\_0\nLogon Account:\tN130042\nSource Workstation:\t12-U0054\nError Code:\t0x0",  
"opcode": "Info",  
"type": "wineventlog",  
"tags": [  
"ActiveDirectory",  
"\_grokparsefailure"  
],  
"thread\_id": 4928,  
"@timestamp": "2017-03-09T15:56:45.381Z",  
"event\_id": 4776,  
"task": "Credential Validation",  
"provider\_guid": "{54849625-5478-4994-A5BA-3E3B0328C30D}",  
"beat": {  
"hostname": "VMNT656DC",  
"name": "VMNT656DC",  
"version": "5.1.1"  
},  
"@version": "1",  
"source\_name": "Microsoft-Windows-Security-Auditing"  
},  
"fields": {  
"@timestamp": [  
1489075005381  
]  
},  
"sort": [  
1489075005381  
]  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 14, 2017, 2:20pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/19 "2017-03-14T14:20:43Z")

</div>

I don't understand what you're asking.

---

<div class="post-metadata">

**Author:** ![Grenouille06](https://avatars.discourse-cdn.com/v4/letter/g/48db29/32.png) [@Grenouille06](https://discuss.elastic.co/u/Grenouille06)\
**Post date:** [March 14, 2017, 2:57pm UTC](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677/20 "2017-03-14T14:57:12Z")

</div>

excuse me, english is not my native language.

My dictionary.yml contains 15000 entries

yaml file example  
sAMAccountName: displayName  
C583: jane Doe  
C090: John Doe  
C587: Michael Jackson

my filter file

> filter{  
> translate {  
> dictionary\_path =\> "/etc/logstash/mutate/ExportADLDS.yml"  
> field =\> "[event\_data][TargetUserName]"  
> destination =\> "[username]"  
> remove\_field =\> ["@version", "@timestamp"]  
> override =\> true  
> }  
> }

The difficulty I have is matching the field "[event\_data][TargetUserName]" of my event in ES with the "sAMAccountName" of my dictionary file. If e value is present, add a new field "[username]" in my event (and it is the value of the "displayName" from my dictionary.

EXAMPLE : if in the event the field "[event\_data][TargetUserName]: "C587", I want a new field "[username]" to be added in my event with the value "Michael Jackson".

Thanks for your help, it is very hard to use filters

[Next page](https://discuss.elastic.co/t/add-field-from-csv-to-event-log-send-by-logstash/77677.md?page=2)
