# How to replace field values from json external file?

**URL:** <https://discuss.elastic.co/t/how-to-replace-field-values-from-json-external-file/286475>\
**Category:** Logstash\
**Created:** [October 12, 2021, 10:41am UTC](https://discuss.elastic.co/t/how-to-replace-field-values-from-json-external-file/286475 "2021-10-12T10:41:05Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![padamrai](https://avatars.discourse-cdn.com/v4/letter/p/3da27b/32.png) [@padamrai](https://discuss.elastic.co/u/padamrai)\
**Post date:** [October 12, 2021, 10:41am UTC](https://discuss.elastic.co/t/how-to-replace-field-values-from-json-external-file/286475/1 "2021-10-12T10:41:06Z")

</div>

I am getting messages from RabbitMQ with field name ResponseCode. Response code consist of short codes like , 00, 01, 02 and so on. I want to replace those values will full form. I have another json key:values pair file where all information is written related to those responsecodes. I am confuse how to achieve this use case.

One Condition is to use if condition of each Response code and replace with full Form but problem is that I have 500+ codes using that much if condition is difficult and wastage of processing power.

Need your help to resolve this problem? Is it possible?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [October 12, 2021, 11:03am UTC](https://discuss.elastic.co/t/how-to-replace-field-values-from-json-external-file/286475/2 "2021-10-12T11:03:59Z")

</div>

You might be able to use the translate filter with the [dictionary\_path](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-dictionary_path) option depending on how that JSON is formatted.

---

<div class="post-metadata">

**Author:** ![padamrai](https://avatars.discourse-cdn.com/v4/letter/p/3da27b/32.png) [@padamrai](https://discuss.elastic.co/u/padamrai)\
**Post date:** [October 12, 2021, 11:07am UTC](https://discuss.elastic.co/t/how-to-replace-field-values-from-json-external-file/286475/3 "2021-10-12T11:07:56Z")

</div>

Thanks for response sir, I have json file with this format,

```auto
{
   "00":"Approved",
   "01":"Error",
   "02":"Pending"
 }

```

and this file contains more than 500 codes.  
How to read this file in logstash and compare with incoming field from RabbitMQ and replace codes with values in the files.

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [October 12, 2021, 11:11am UTC](https://discuss.elastic.co/t/how-to-replace-field-values-from-json-external-file/286475/4 "2021-10-12T11:11:30Z")

</div>

Untested, but by looking at the documentation I would try this.

```auto
filter { 
 translate {
  field => "[ResponseCode]"
  destination => "[ResponseText]"
  dictionary_path => "/etc/logstash/file.json"
 }
}

```

---

<div class="post-metadata">

**Author:** ![padamrai](https://avatars.discourse-cdn.com/v4/letter/p/3da27b/32.png) [@padamrai](https://discuss.elastic.co/u/padamrai)\
**Post date:** [October 12, 2021, 11:16am UTC](https://discuss.elastic.co/t/how-to-replace-field-values-from-json-external-file/286475/5 "2021-10-12T11:16:16Z")

</div>

```auto
 if[ResponseCode] == "00"{
        mutate {
            replace => { "ResponseCode" => "Approved" }
        }
    }

```

By using if condition we are performing like that. I am getting still confused about how to compare values in file and field, In Your code, we are getting field name and file path then what is function of destination?

---

<div class="post-metadata">

**Author:** ![aaron-nimocks](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aaron-nimocks/32/73965_2.png) [@aaron-nimocks](https://discuss.elastic.co/u/aaron-nimocks)\
**Post date:** [October 12, 2021, 11:19am UTC](https://discuss.elastic.co/t/how-to-replace-field-values-from-json-external-file/286475/6 "2021-10-12T11:19:42Z")

</div>

Please read the documentation for this plugin as it will cover most of your questions. You can use [Destination](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-destination) or [Target](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-target) for this if it meets your requirements.

---

<div class="post-metadata">

**Author:** ![padamrai](https://avatars.discourse-cdn.com/v4/letter/p/3da27b/32.png) [@padamrai](https://discuss.elastic.co/u/padamrai)\
**Post date:** [October 12, 2021, 11:20am UTC](https://discuss.elastic.co/t/how-to-replace-field-values-from-json-external-file/286475/7 "2021-10-12T11:20:44Z")

</div>

Okay Sir, Thank You for your time.  
Anyone have much idea about it.

---

<div class="post-metadata">

**Author:** ![padamrai](https://avatars.discourse-cdn.com/v4/letter/p/3da27b/32.png) [@padamrai](https://discuss.elastic.co/u/padamrai)\
**Post date:** [October 12, 2021, 12:01pm UTC](https://discuss.elastic.co/t/how-to-replace-field-values-from-json-external-file/286475/8 "2021-10-12T12:01:36Z")

</div>

Sir this works exactly what I wanted. thank you so so much. It is like a miracle for me. 🥰 😍

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2021, 12:01pm UTC](https://discuss.elastic.co/t/how-to-replace-field-values-from-json-external-file/286475/9 "2021-11-09T12:01:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
