# Global variables in an external file

**URL:** <https://discuss.elastic.co/t/global-variables-in-an-external-file/109378>\
**Category:** Logstash\
**Created:** [November 28, 2017, 12:00pm UTC](https://discuss.elastic.co/t/global-variables-in-an-external-file/109378 "2017-11-28T12:00:09Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ea1987](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ea1987/32/51356_2.png) [@ea1987](https://discuss.elastic.co/u/ea1987)\
**Post date:** [November 28, 2017, 12:00pm UTC](https://discuss.elastic.co/t/global-variables-in-an-external-file/109378/1 "2017-11-28T12:00:09Z")

</div>

Hi guys,  
I would like logstash to use global variables defined in an external file and use them in each event elaboration for doing something like this:

external file:  
field1 = [value1,value2]

meta logstash Language:

if the\_value\_of\_an\_event\_field in field1  
drop event

Moreover I would like my solution to be dynamic so, for example, I can extend field 1 to [value1, value2, value3] without stopping logstash and so on..

I tried different solutions (like reading external file via filebeat or via logstash input file, but they, of course, read it one time only; using grok and external path pattern but that's not working cause I don't want to match patterns..).

Any help or suggestion will be appreciated.  
Thank you guys.

Andrea

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 28, 2017, 3:03pm UTC](https://discuss.elastic.co/t/global-variables-in-an-external-file/109378/2 "2017-11-28T15:03:33Z")

</div>

Have you looked at the translate filter?

---

<div class="post-metadata">

**Author:** ![ea1987](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ea1987/32/51356_2.png) [@ea1987](https://discuss.elastic.co/u/ea1987)\
**Post date:** [December 5, 2017, 1:29pm UTC](https://discuss.elastic.co/t/global-variables-in-an-external-file/109378/3 "2017-12-05T13:29:33Z")

</div>

I solved using Ruby plugin, reading Values from file and saving them inside an array. Of course, this operation will be performed every time, but this will let pipeline to dynamic change read Values.

```
ruby {
	code => "messaggio = ''
			 array = File.open('/home/elastic/Elastic/configurations/whitelist.txt').readlines.map(&:strip).each do |line| messaggio << line end				 
			 event.set('[white_list]', array)
			 "		 
}

```

Thank you for your suggestions, anyway 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 2, 2018, 1:29pm UTC](https://discuss.elastic.co/t/global-variables-in-an-external-file/109378/4 "2018-01-02T13:29:39Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
