# Compare two datasets

**URL:** <https://discuss.elastic.co/t/compare-two-datasets/129006>\
**Category:** Logstash\
**Created:** [April 22, 2018, 1:27pm UTC](https://discuss.elastic.co/t/compare-two-datasets/129006 "2018-04-22T13:27:44Z")\
**Posts on this page:** 1\
**Showing post:** 5

<div class="post-metadata">

**Author:** ![counterf](https://avatars.discourse-cdn.com/v4/letter/c/9d8465/32.png) [@counterf](https://discuss.elastic.co/u/counterf)\
**Post date:** [April 23, 2018, 12:02am UTC](https://discuss.elastic.co/t/compare-two-datasets/129006/5 "2018-04-23T00:02:39Z")

</div>

The translate is not working.

I am using packetbeat to send network activity.

Here is my conf:

> # input section
> 
> input {  
> beats {  
> port =\> 5044  
> }  
> }
> 
> filter {  
> translate {  
> field =\> "dest.ip"  
> destination =\> "malicious\_IP"  
> dictionary\_path =\> '/opt/logstash/maliciousIPV4.yaml'  
> override =\> true  
> }
> 
> translate {  
> field =\> "source.ip"  
> destination =\> "malicious\_IP"  
> dictionary\_path =\> '/opt/logstash/maliciousIPV4.yaml'  
> override =\> true  
> }
> 
> }  
> output {  
> elasticsearch {  
> hosts =\> localhost  
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
> }  
> stdout {  
> codec =\> rubydebug  
> }  
> }

I can see the logs coming, they appear in Kibana, but the translation just doesnt work.

Here is the content of the dictionary

> "216.46.173.126": "true"  
> "180.179.174.219": "true"  
> "204.77.168.241": "true"  
> "65.39.197.164": "true"  
> "80.91.33.133": "true"  
> "84.208.15.12": "true"  
> "74.125.60.158": "true"  
> "8.8.8.8": "true"  
> "200.221.2.45": "true"  
> "186.232.248.40": "true"

The translate plugin is installed.

Any idea?

---

_[View the full topic](https://discuss.elastic.co/t/compare-two-datasets/129006)._
