# How to use Translate plugin in grok filter

**URL:** <https://discuss.elastic.co/t/how-to-use-translate-plugin-in-grok-filter/100830>\
**Category:** Logstash\
**Created:** [September 18, 2017, 7:28am UTC](https://discuss.elastic.co/t/how-to-use-translate-plugin-in-grok-filter/100830 "2017-09-18T07:28:56Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![sreejiths](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@sreejiths](https://discuss.elastic.co/u/sreejiths)\
**Post date:** [September 18, 2017, 7:28am UTC](https://discuss.elastic.co/t/how-to-use-translate-plugin-in-grok-filter/100830/1 "2017-09-18T07:28:56Z")

</div>

[https://www.elastic.co/guide/en/logstash/5.2/plugins-filters-translate.html#plugins-filters-translate-dictionary\_path](https://www.elastic.co/guide/en/logstash/5.2/plugins-filters-translate.html#plugins-filters-translate-dictionary_path)

Hi , I have a specific requirement , I will have a csv file with data as below , what i want is if the message is coming from specified ip address or ip address range(Source of message/input) , need to add a tag in the next column of the csv sheet . Will translate plugin help in achieve ? if yes can someone provide some used cases or examples ? If No ,,can advice on how to achieve the above specific requirement

IP Address Dept  
10.12.1.93 HR  
10.12.1.102 TECH  
10.15.0.206 FIN  
10.12.8.50 HR  
10.15.116.225 FIN  
10.12.1.183 TECH

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 18, 2017, 7:32am UTC](https://discuss.elastic.co/t/how-to-use-translate-plugin-in-grok-filter/100830/2 "2017-09-18T07:32:39Z")

</div>

Yes it can do that.

Just point the filter at the field that has the IP and it'll do the lookup.

---

<div class="post-metadata">

**Author:** ![sreejiths](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@sreejiths](https://discuss.elastic.co/u/sreejiths)\
**Post date:** [September 18, 2017, 7:46am UTC](https://discuss.elastic.co/t/how-to-use-translate-plugin-in-grok-filter/100830/3 "2017-09-18T07:46:40Z")

</div>

Can you please advice the filter block , sorry I am bit new to ELK

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 18, 2017, 7:51am UTC](https://discuss.elastic.co/t/how-to-use-translate-plugin-in-grok-filter/100830/4 "2017-09-18T07:51:29Z")

</div>

FYI we’ve renamed ELK to the Elastic Stack, otherwise Beats feels left out 😉

```auto
translate {
  field => "Put your field name here"
  dictionary_path => "/path/to/the/dictionary/file"
}

```

That is really all you need to get started.

---

<div class="post-metadata">

**Author:** ![sreejiths](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@sreejiths](https://discuss.elastic.co/u/sreejiths)\
**Post date:** [September 18, 2017, 8:21am UTC](https://discuss.elastic.co/t/how-to-use-translate-plugin-in-grok-filter/100830/5 "2017-09-18T08:21:54Z")

</div>

Sorry , will keep a note on Elastic stack

Will the below work , i doubt ..Honestly i didnt get logic of this plugin ..🙁

translate {  
dictionary\_path =\> "/etc/logstash/hosts.csv"  
field =\> "host"  
destination =\> "Dept"  
}

Below will be content of CSV file  
IP Address Dept  
10.12.1.93 HR  
10.12.1.102 TECH  
10.15.0.206 FIN  
10.12.8.50 HR  
10.15.116.225 FIN  
10.12.1.183 TECH

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 18, 2017, 8:23am UTC](https://discuss.elastic.co/t/how-to-use-translate-plugin-in-grok-filter/100830/6 "2017-09-18T08:23:34Z")

</div>

No, the format of the dictionary is wrong.  
See [https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-dictionary\_path](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-dictionary_path)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 16, 2017, 8:24am UTC](https://discuss.elastic.co/t/how-to-use-translate-plugin-in-grok-filter/100830/7 "2017-10-16T08:24:03Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
