# Cannot translate value inside fields

**URL:** <https://discuss.elastic.co/t/cannot-translate-value-inside-fields/217351>\
**Category:** Logstash\
**Created:** [January 31, 2020, 10:43am UTC](https://discuss.elastic.co/t/cannot-translate-value-inside-fields/217351 "2020-01-31T10:43:55Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![BIs1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bis1/32/60811_2.png) [@BIs1](https://discuss.elastic.co/u/BIs1)\
**Post date:** [January 31, 2020, 10:43am UTC](https://discuss.elastic.co/t/cannot-translate-value-inside-fields/217351/1 "2020-01-31T10:43:55Z")

</div>

Hi,

I am using logstash 7.3.1 and trying to translate value inside the field after renaming. Basically I want to use translate plugin to translate the value inside the field and populate in same field or different field. If possible don`t want to use dictionary file and point it to file location. I dont know where am I going wrong as its not translating values.

filter {  
if [type] == "logs" {  
grok {  
match =\> { "message" =\> ["%{TIMESTAMP\_ISO8601:timestamp}%{DATA:loglevel}%{SYSLOGHOST:loglevel}%{DATA:source}%{GREEDYDATA:message}"] }  
}  
mutate {  
rename =\> { "[loglevel]" =\> "[syslog\_severity]" }  
}  
mutate {  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}

```
translate {
field => "loglevel"
destination => "syslog_severity"
 dictionary => {
  "TRACE" => "DEBUG"
  "DEBUG" => "DEBUG"
  "INFO" => "INFO"
  "WARN" => "WARN"
  "ERROR" => "ERROR"
  "FATAL" => "CRITICAL"
}
  remove_field => "loglevel"

```

}  
}  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 31, 2020, 3:15pm UTC](https://discuss.elastic.co/t/cannot-translate-value-inside-fields/217351/2 "2020-01-31T15:15:44Z")

</div>

The [loglevel] field will not exist when the translate filter executes because you have previously used mutate+rename to rename it.

---

<div class="post-metadata">

**Author:** ![BIs1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bis1/32/60811_2.png) [@BIs1](https://discuss.elastic.co/u/BIs1)\
**Post date:** [February 12, 2020, 2:07pm UTC](https://discuss.elastic.co/t/cannot-translate-value-inside-fields/217351/3 "2020-02-12T14:07:16Z")

</div>

Thanks that fixed the problem.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 11, 2020, 2:13pm UTC](https://discuss.elastic.co/t/cannot-translate-value-inside-fields/217351/4 "2020-03-11T14:13:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
