# Dynamic configuration of logstash

**URL:** <https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358>\
**Category:** Logstash\
**Created:** [February 22, 2016, 6:37am UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358 "2016-02-22T06:37:46Z")\
**Posts on this page:** 13\
**Page:** 1

<div class="post-metadata">

**Author:** ![harshafrnd4u](https://avatars.discourse-cdn.com/v4/letter/h/fbc32d/32.png) [@harshafrnd4u](https://discuss.elastic.co/u/harshafrnd4u)\
**Post date:** [February 22, 2016, 6:37am UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/1 "2016-02-22T06:37:46Z")

</div>

Hi,

Is there anyway to load logstash configuration dynamically using database or some filesystem. ?  
The usecase is lets say i have multiple apaches where I am getting data from and I am getting data with their ips (each record has field 'ip' of apache server ip adress). We need to get host names for each ip and stamp on each record and send it to elasticsearch. But I have mapping of ip addresses to host names in my filesystem, So i need to read mapping from there dynamically and stamp host name on each record.

Thanks  
Harsha

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [February 22, 2016, 9:09am UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/2 "2016-02-22T09:09:34Z")

</div>

Logstash 2.2 supports dynamic configuration reloads (see [https://www.elastic.co/blog/logstash-lines-2016-02-09](https://www.elastic.co/blog/logstash-lines-2016-02-09)) but unless you can use the [dns filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dns.html) this sounds like a job for the [translate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html).

---

<div class="post-metadata">

**Author:** ![seefood](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/seefood/32/7939_2.png) [@seefood](https://discuss.elastic.co/u/seefood)\
**Post date:** [February 23, 2016, 4:08pm UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/3 "2016-02-23T16:08:43Z")

</div>

sounds to me like the shipper on the sending machine should stamp the events with the hostname if you don't want to DNS-resolve them all. it's not something that should be handled by the collector itself, IMHO, therefore should not require a change in its logstash config.

---

<div class="post-metadata">

**Author:** ![harshafrnd4u](https://avatars.discourse-cdn.com/v4/letter/h/fbc32d/32.png) [@harshafrnd4u](https://discuss.elastic.co/u/harshafrnd4u)\
**Post date:** [February 23, 2016, 4:39pm UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/4 "2016-02-23T16:39:22Z")

</div>

Thanks for prompt response. I think translate can solve my problem giving local file as an input to it. I will explore little bit more and will come back.

---

<div class="post-metadata">

**Author:** ![harshafrnd4u](https://avatars.discourse-cdn.com/v4/letter/h/fbc32d/32.png) [@harshafrnd4u](https://discuss.elastic.co/u/harshafrnd4u)\
**Post date:** [February 23, 2016, 4:41pm UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/5 "2016-02-23T16:41:31Z")

</div>

This is one of requirement like mapping hostname. There are few more where I want to map something with something, like tagging request with some api name eg:based on request I will add a field apiname where I should get this mapping from some database or filesystem. I think translate can solve my problem.

---

<div class="post-metadata">

**Author:** ![Joe\_Lawson](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/joe_lawson/32/3390_2.png) [@Joe\_Lawson](https://discuss.elastic.co/u/Joe_Lawson)\
**Post date:** [February 23, 2016, 6:06pm UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/6 "2016-02-23T18:06:55Z")

</div>

If you only have to update the config like hostname you can just make a  
template config with keys and then run a sed command or other template  
merger prior to starting up Logstash. I did that to inject hostname and  
Cloud metadata on ephemeral hosts that used Logstash.

---

<div class="post-metadata">

**Author:** ![simmel](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/simmel/32/48040_2.png) [@simmel](https://discuss.elastic.co/u/simmel)\
**Post date:** [March 8, 2016, 7:34am UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/7 "2016-03-08T07:34:32Z")

</div>

Not sure if I misunderstood something, but there's always  
[https://www.elastic.co/guide/en/logstash/current/plugins-filters-environment.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-environment.html)

---

<div class="post-metadata">

**Author:** ![harshafrnd4u](https://avatars.discourse-cdn.com/v4/letter/h/fbc32d/32.png) [@harshafrnd4u](https://discuss.elastic.co/u/harshafrnd4u)\
**Post date:** [March 8, 2016, 7:52am UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/8 "2016-03-08T07:52:35Z")

</div>

translate filter plugin solved my case. Thanks for your time 🙂

---

<div class="post-metadata">

**Author:** ![shapiroj](https://avatars.discourse-cdn.com/v4/letter/s/5f9b8f/32.png) [@shapiroj](https://discuss.elastic.co/u/shapiroj)\
**Post date:** [March 25, 2016, 6:43pm UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/9 "2016-03-25T18:43:09Z")

</div>

Is it true that 2.2 supports this? I don't see anything in the docs or repo to indicate this? It seems like it has only been back ported to 2.3.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 25, 2016, 8:34pm UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/10 "2016-03-25T20:34:20Z")

</div>

> Is it true that 2.2 supports this? I don't see anything in the docs or repo to indicate this? It seems like it has only been back ported to 2.3.

You're right. It was in the blog post announcing the availability of the 2.2 release and I incorrectly inferred that it was included in 2.2.

---

<div class="post-metadata">

**Author:** ![harshafrnd4u](https://avatars.discourse-cdn.com/v4/letter/h/fbc32d/32.png) [@harshafrnd4u](https://discuss.elastic.co/u/harshafrnd4u)\
**Post date:** [April 14, 2016, 7:05am UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/11 "2016-04-14T07:05:04Z")

</div>

With translate plugin and I am using yml dictionary from a file. When I change this file translate plugin is not picking latest changes. Is there any way to reload dictionary automatically whenever it changes?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [April 14, 2016, 7:08am UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/12 "2016-04-14T07:08:03Z")

</div>

By default Logstash will reload the file every five minutes if it has changed (configurable with the [`refresh_interval` option](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-refresh_interval)).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:02am UTC](https://discuss.elastic.co/t/dynamic-configuration-of-logstash/42358/13 "2017-07-06T05:02:21Z")

</div>


