# How to Create a Watchlist/Lookup Tables

**URL:** <https://discuss.elastic.co/t/how-to-create-a-watchlist-lookup-tables/38228>\
**Category:** Logstash\
**Created:** [December 31, 2015, 1:00pm UTC](https://discuss.elastic.co/t/how-to-create-a-watchlist-lookup-tables/38228 "2015-12-31T13:00:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![praveen\_siem](https://avatars.discourse-cdn.com/v4/letter/p/e9a140/32.png) [@praveen\_siem](https://discuss.elastic.co/u/praveen_siem)\
**Post date:** [December 31, 2015, 1:00pm UTC](https://discuss.elastic.co/t/how-to-create-a-watchlist-lookup-tables/38228/1 "2015-12-31T13:00:12Z")

</div>

Dear Team,

Do anyone have idea on how do we create a watchlist in ELK. In other terms lookup tables. This specifies a range of values say 50 or 100 or more in a single file. And save it as .csv or .txt

For Ex: there are around 50-100 source IP addresses and each cannot be mentioned in the condition in the query. So we put it in a file and call that file in the condition of the query.

How do we do this in creating a query in ELK, and that too in logstash.

Please throw some light if someone has come across such situation.

Best Regards-  
Praveen Kamble

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 1, 2016, 9:51pm UTC](https://discuss.elastic.co/t/how-to-create-a-watchlist-lookup-tables/38228/2 "2016-01-01T21:51:19Z")

</div>

There is the translate filter that might work.

---

<div class="post-metadata">

**Author:** ![praveen\_siem](https://avatars.discourse-cdn.com/v4/letter/p/e9a140/32.png) [@praveen\_siem](https://discuss.elastic.co/u/praveen_siem)\
**Post date:** [January 11, 2016, 9:44am UTC](https://discuss.elastic.co/t/how-to-create-a-watchlist-lookup-tables/38228/3 "2016-01-11T09:44:09Z")

</div>

Mark,

Thanks. Can you just help out or share any guide indicating so as how to prepare the "translate filter".

Best Regards-  
Praveen

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 12, 2016, 12:44am UTC](https://discuss.elastic.co/t/how-to-create-a-watchlist-lookup-tables/38228/4 "2016-01-12T00:44:55Z")

</div>

[https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) is the best place to start.

---

<div class="post-metadata">

**Author:** ![praveen\_siem](https://avatars.discourse-cdn.com/v4/letter/p/e9a140/32.png) [@praveen\_siem](https://discuss.elastic.co/u/praveen_siem)\
**Post date:** [January 13, 2016, 10:15am UTC](https://discuss.elastic.co/t/how-to-create-a-watchlist-lookup-tables/38228/5 "2016-01-13T10:15:33Z")

</div>

Thanks for sharing the link, Mark.

We tried to install the "translate filter" plug-in on the log stash 1.4.2- modified version, while installing we are getting the error-

**Can only install contrib at this time... Exiting.**.

Suggest the possible resolution from your end.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 13, 2016, 10:23am UTC](https://discuss.elastic.co/t/how-to-create-a-watchlist-lookup-tables/38228/6 "2016-01-13T10:23:04Z")

</div>

I'd start by upgrading, 1.4 is _really_ old.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:15am UTC](https://discuss.elastic.co/t/how-to-create-a-watchlist-lookup-tables/38228/7 "2017-07-06T05:15:54Z")

</div>


