# How to reference value of field in translate?

**URL:** <https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561>\
**Category:** Logstash\
**Created:** [November 12, 2019, 4:32pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561 "2019-11-12T16:32:30Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrew22](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Post date:** [November 12, 2019, 4:32pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/1 "2019-11-12T16:32:30Z")

</div>

I would like to use the device name I have in the dictionary\_path in the translate filter but I am having issues with it. is it even possible?

something like

translate {  
field =\> " **name**"  
destination =\> "lookUp"  
dictionary\_path =\> "/ **name**.yml"  
}

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [November 12, 2019, 6:04pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/2 "2019-11-12T18:04:24Z")

</div>

Hi,

yes it is possible I am using the `translate` feature a lot.

```auto
translate {
  field => "name"
  destination => "lookUp"
  dictionary_path => "name.yml"
}

```

the issue is with `/name.yml` you say to logstash to look at the root folder `/`. You just want to use `name.yml` if it is inside the same directory as your pipeline is.

---

<div class="post-metadata">

**Author:** ![Andrew22](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Post date:** [November 12, 2019, 6:12pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/3 "2019-11-12T18:12:32Z")

</div>

but will **name**.yml be the value inside the field "name"?

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [November 12, 2019, 6:20pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/4 "2019-11-12T18:20:06Z")

</div>

[https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) No that is the full path to the file where you store your map.

Let's say you want to replace the short hostname of your machine with a full name.  
shortname = 'philippMacBook'  
fullname = 'philippkahrsFancyMacBookWithTouchBar'

```auto
translate{
  field => "shortname"
  destination => "fullname"
  dictionary_path => "names.yml"
}

```

Your `names.yml` would look like this

```auto
philippMacBook: "philippkahrsFancyMacBookWithTouchBar"

```

so in the names.yml you need to have the value of the field you are looking for stored as a key and the value you want to have in destination stored as a value.

I hope that helps

---

<div class="post-metadata">

**Author:** ![Andrew22](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Post date:** [November 12, 2019, 6:30pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/5 "2019-11-12T18:30:26Z")

</div>

sorry I mean I want to use the value stored in the **name** field like a variable to look up the specific .yml file for the translation

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [November 12, 2019, 6:34pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/6 "2019-11-12T18:34:50Z")

</div>

I do not know to be honest. I think everything as a value to `dictionary_path` is treated as a string and does not resolve variables.

Could you explain what you are trying to achieve with the translate filter?

---

<div class="post-metadata">

**Author:** ![Andrew22](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Post date:** [November 12, 2019, 6:39pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/7 "2019-11-12T18:39:18Z")

</div>

I am trying to look up a number associated with a name but many names have the same number so I would need multiple different .yml files to match the correct names and numbers.. if that makes sense

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [November 12, 2019, 6:46pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/8 "2019-11-12T18:46:20Z")

</div>

Ok so from my understanding you have a single key (name) that has multiple values (numbers)?  
You would still need to put them all into a single yaml or json with dictionaries.

> It is possible to provide multi-valued dictionary values. When using a YAML or JSON dictionary, you can have the value as a hash (map) or an array datatype.  
> [https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-dictionary](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-dictionary)

Let's say you have the following key values.

```yaml
philippsMacBook:
    - philipp
    - macbook
    - touchbar
    - cat

```

your translate should look like this

```auto
translate{
  field => "shortname"
  destination => "[fullnames]"
  dictionary_path => "names.yml"
}

```

since you are writing an array back. But you still need to combine all your yaml files into one.

---

<div class="post-metadata">

**Author:** ![Andrew22](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Post date:** [November 12, 2019, 6:57pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/9 "2019-11-12T18:57:47Z")

</div>

i think i have not been very clear and that's my mistake let me try again

i have names of brands and each brand has multiple numbers associated with them ( part number) and each number is associated with a model but the problem is i have the same number used often for each of the brands.

so say i have fields **brand** and **part\_number** and i was to translate the part number to the correct model based on the brand

translate {  
field =\> "part\_number"  
destination =\> "model"  
dictionary\_path =\> %{brand}.yml  
}

so say Apple was in the field **brand** it would use apple.yml in place of %{brand}.yml like a variable

again i do not know if this is possible i was hoping that i could use a variable

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [November 12, 2019, 7:01pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/10 "2019-11-12T19:01:05Z")

</div>

I understand your concept now. I do not think that this is possible, since the value of `dictionary_path` will possible be passed directly, you could open a github issue on that one here [https://github.com/logstash-plugins/logstash-filter-translate](https://github.com/logstash-plugins/logstash-filter-translate) maybe they know more.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 12, 2019, 7:02pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/11 "2019-11-12T19:02:08Z")

</div>

> [@Andrew22](#):
>
> again i do not know if this is possible i was hoping that i could use a variable

No, the value of dictionary\_path is passed straight to IO.read, it is not sprintf'd first.

---

<div class="post-metadata">

**Author:** ![Andrew22](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Post date:** [November 12, 2019, 7:27pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/12 "2019-11-12T19:27:29Z")

</div>

i see..

is it possible to use nested dictionaries with translate to accomplish what i want to do? for example:

apple:  
12345: macbook

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [November 12, 2019, 7:37pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/13 "2019-11-12T19:37:31Z")

</div>

No not that I know.

the only thing you could do is something like this (pseudocode)

```auto
if(name == "Apple"){
    translate{..... dictionary_path: "apple.yml"}
}else if (name == "Samsung"){
    translate{.... dictionary_path: "samsung.yml"}
)

```

you would need to create a lot of translates and if queries.

---

<div class="post-metadata">

**Author:** ![Andrew22](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Post date:** [November 12, 2019, 7:40pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/14 "2019-11-12T19:40:18Z")

</div>

yeah unfortunately I would potentially need to create 1000s

---

<div class="post-metadata">

**Author:** ![philippkahr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/philippkahr/32/100137_2.png) [@philippkahr](https://discuss.elastic.co/u/philippkahr)\
**Post date:** [November 12, 2019, 8:08pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/15 "2019-11-12T20:08:15Z")

</div>

Then I would suggest opening an issue at the github repo I linked above.

---

<div class="post-metadata">

**Author:** ![manud](https://avatars.discourse-cdn.com/v4/letter/m/edb3f5/32.png) [@manud](https://discuss.elastic.co/u/manud)\
**Post date:** [November 13, 2019, 3:32am UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/16 "2019-11-13T03:32:31Z")

</div>

If you're willing to transform your translate data a bit you could structure the file like:

```auto
Apple_12345: macbook
Apple_12346: iphone
Dell_12345: laptop

```

Then construct a new field to use for your translate:

```auto
translate {
    add_field => { "lookup" => "%{brand}_%{part_number}" }
    field => "lookup"
    destination => "model"
    dictionary_path => "translate_file.yml"
    remove_field => ["lookup"]
}

```

---

<div class="post-metadata">

**Author:** ![Andrew22](https://avatars.discourse-cdn.com/v4/letter/a/f6c823/32.png) [@Andrew22](https://discuss.elastic.co/u/Andrew22)\
**Post date:** [November 13, 2019, 1:28pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/17 "2019-11-13T13:28:57Z")

</div>

thank you that is a good work around I will have to try it

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 11, 2019, 1:29pm UTC](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/18 "2019-12-11T13:29:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
