# How could I use in ingest pipeline the Logstash translate filter?

**URL:** <https://discuss.elastic.co/t/how-could-i-use-in-ingest-pipeline-the-logstash-translate-filter/259697>\
**Category:** Elasticsearch\
**Created:** [December 27, 2020, 7:59pm UTC](https://discuss.elastic.co/t/how-could-i-use-in-ingest-pipeline-the-logstash-translate-filter/259697 "2020-12-27T19:59:19Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![marcosvrrs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcosvrrs/32/77073_2.png) [@marcosvrrs](https://discuss.elastic.co/u/marcosvrrs)\
**Post date:** [December 27, 2020, 7:59pm UTC](https://discuss.elastic.co/t/how-could-i-use-in-ingest-pipeline-the-logstash-translate-filter/259697/1 "2020-12-27T19:59:20Z")

</div>

I have a field with some error codes mapped as keyword values that I make some plots. It's not friendly to some people to look at these codes, so I want to change these error codes to a description that I will map as keyword type, and it would be awesome to do this translation when I index my documents with the ingest pipeline.  
I can't use logstash, and I am looking for an alternative way to translate some field values.  
Right now I am doing this with a scripted field directly in kibana.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [December 28, 2020, 1:09am UTC](https://discuss.elastic.co/t/how-could-i-use-in-ingest-pipeline-the-logstash-translate-filter/259697/2 "2020-12-28T01:09:35Z")

</div>

Same concept of what you are doing with a scripted field except if you run that painless script in an ingest pipeline then you only do this once, when the data comes in. Scripted fields calculate every time the record is accessed.

1. Create an ingest pipeline. Recommend researching the [Script Processor](https://www.elastic.co/guide/en/elasticsearch/reference/current/script-processor.html) first.
2. Test ingest pipeline using [Simulate Pipeline API](https://www.elastic.co/guide/en/elasticsearch/reference/7.10/simulate-pipeline-api.html).
3. Define pipeline to run with how you are ingesting your data. Logstash and Beats both have a setting where you identify which pipeline to run.

---

<div class="post-metadata">

**Author:** ![marcosvrrs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcosvrrs/32/77073_2.png) [@marcosvrrs](https://discuss.elastic.co/u/marcosvrrs)\
**Post date:** [January 4, 2021, 6:52pm UTC](https://discuss.elastic.co/t/how-could-i-use-in-ingest-pipeline-the-logstash-translate-filter/259697/3 "2021-01-04T18:52:06Z")

</div>

I tried to do the painless script and had a fatal exception few days ago that scared me a lot, my cluster took a few hours to recover and assign the shards. This exception seems to be a recent problem and I replied in this issue in github: [https://github.com/elastic/elasticsearch/issues/66175](https://github.com/elastic/elasticsearch/issues/66175)

Now that I know that I should not use a return statement, I will try again soon. Thank you for the answer!

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [January 4, 2021, 10:19pm UTC](https://discuss.elastic.co/t/how-could-i-use-in-ingest-pipeline-the-logstash-translate-filter/259697/4 "2021-01-04T22:19:55Z")

</div>

Why not just add the description using the enrich processor, pretty much exactly made for this use case.

> **[Enrich your data | Elasticsearch Reference \[7.10\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/ingest-enriching-data.html)**

---

<div class="post-metadata">

**Author:** ![marcosvrrs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcosvrrs/32/77073_2.png) [@marcosvrrs](https://discuss.elastic.co/u/marcosvrrs)\
**Post date:** [January 10, 2021, 2:36pm UTC](https://discuss.elastic.co/t/how-could-i-use-in-ingest-pipeline-the-logstash-translate-filter/259697/5 "2021-01-10T14:36:32Z")

</div>

This is a very nice way of dealing with my problem. I will try tomorrow and report back. Thank you guys so much for helping me with two distinct solutions.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 7, 2021, 2:36pm UTC](https://discuss.elastic.co/t/how-could-i-use-in-ingest-pipeline-the-logstash-translate-filter/259697/6 "2021-02-07T14:36:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
