# Database request

**URL:** <https://discuss.elastic.co/t/database-request/42596>\
**Category:** Logstash\
**Created:** [February 24, 2016, 2:54pm UTC](https://discuss.elastic.co/t/database-request/42596 "2016-02-24T14:54:08Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Justin\_V](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@Justin\_V](https://discuss.elastic.co/u/Justin_V)\
**Post date:** [February 24, 2016, 2:54pm UTC](https://discuss.elastic.co/t/database-request/42596/1 "2016-02-24T14:54:08Z")

</div>

Hello,

I didn't find the answer in other topics, so I post a new one.  
Here's the thing : In my logs, I have some id's, who are totally not representative of what they are exactly.  
So my question is : _After_ having "grokked" the logs, is it possible to query a database with the value of created fields ?  
If yes, I suppose that creating new field with the answer is not always funny with the types of return, right ?

If someone can enlighten me on the fact that it is possible, or not.

Thank you in advance

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 24, 2016, 6:03pm UTC](https://discuss.elastic.co/t/database-request/42596/2 "2016-02-24T18:03:59Z")

</div>

I think the [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) and [elasticsearch](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html) filters are the ones closest to what you need.

---

<div class="post-metadata">

**Author:** ![Wayne\_Taylor](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wayne_taylor/32/45984_2.png) [@Wayne\_Taylor](https://discuss.elastic.co/u/Wayne_Taylor)\
**Post date:** [February 25, 2016, 12:08am UTC](https://discuss.elastic.co/t/database-request/42596/3 "2016-02-25T00:08:29Z")

</div>

Hi Justin\_V I just achieved something similar with a dictionary path yaml file using translate. See the following thread I where I was finally able to get this all working:

> [@Need some help with Geo Enrichment - SOLVED](https://discuss.elastic.co/t/need-some-help-with-geo-enrichment-solved/42340/9):
>
> Really need some help warkolm, banging my head on this one frowning Here is what I've been able to do thus far: Add in a filter mutate to split airport by the ',' so we now have an array from the string containing the latitude and longitude Add in a filter mutate to add the fields called latitude and longitude defined as airport[0] and airport[1] Then add in a filter mutate to convert them from string which is what natively is happening into a float In filter mutate name the longitude and l…

---

<div class="post-metadata">

**Author:** ![Justin\_V](https://avatars.discourse-cdn.com/v4/letter/j/fbc32d/32.png) [@Justin\_V](https://discuss.elastic.co/u/Justin_V)\
**Post date:** [February 25, 2016, 7:49am UTC](https://discuss.elastic.co/t/database-request/42596/4 "2016-02-25T07:49:45Z")

</div>

Thanks for the propositions, I will try these.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:09am UTC](https://discuss.elastic.co/t/database-request/42596/5 "2017-07-06T05:09:47Z")

</div>


