# Check if field value is present at certain file

**URL:** <https://discuss.elastic.co/t/check-if-field-value-is-present-at-certain-file/84066>\
**Category:** Logstash\
**Created:** [April 28, 2017, 10:04pm UTC](https://discuss.elastic.co/t/check-if-field-value-is-present-at-certain-file/84066 "2017-04-28T22:04:23Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![prodrg](https://avatars.discourse-cdn.com/v4/letter/p/3bc359/32.png) [@prodrg](https://discuss.elastic.co/u/prodrg)\
**Post date:** [April 28, 2017, 10:04pm UTC](https://discuss.elastic.co/t/check-if-field-value-is-present-at-certain-file/84066/1 "2017-04-28T22:04:23Z")

</div>

Hello everybody, I have the following case to solve:

There is a list of elements that are on a file. There is an specific input from Logstash that I need to correlate with that file, by checking if a value X on a field Y matches an element on that list. If that's true, Logstash must create a new field on the entry indicating some kind of information about the matching.

I know this can be done with a filter plugin, but I don't know which one (if there are any). I do something similar with translate, but the file is just a list, not a dictionary, and it is downloaded each hour, so the idea is not to touch it.

Any help or tips? Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 26, 2017, 10:08pm UTC](https://discuss.elastic.co/t/check-if-field-value-is-present-at-certain-file/84066/2 "2017-05-26T22:08:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
