# IP Address and Dictionary | New Field as String

**URL:** <https://discuss.elastic.co/t/ip-address-and-dictionary-new-field-as-string/61544>\
**Category:** Logstash\
**Created:** [September 26, 2016, 10:42pm UTC](https://discuss.elastic.co/t/ip-address-and-dictionary-new-field-as-string/61544 "2016-09-26T22:42:10Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![dneto](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dneto/32/11152_2.png) [@dneto](https://discuss.elastic.co/u/dneto)\
**Post date:** [September 26, 2016, 10:42pm UTC](https://discuss.elastic.co/t/ip-address-and-dictionary-new-field-as-string/61544/1 "2016-09-26T22:42:10Z")

</div>

Hi Friends,

I'm using logstash as syslog server to my firewall traffic. I have two IP fields: ip\_dst and ip\_src.  
I need to translate them to HOSTNAMES or some ALIAS against a dictionary, so need create 2 new fields and get these IP data to string data. (Not convert, because I want to keep original).

Since the translate works only with string values, I tried to create 2 new fields and copy source IP values as string, but i'm getting crash on logstash.

```
if "_grokparsefailure" not in [tags] and [type] == "firewall-traffic" {
       mutate {
               add_field => { "ip_dst_str" => "%{ip_dst}" }
               convert => { "ip_dst_str" => "string" }
               add_field => { "ip_src_str" => "%{ip_src}" }
               convert => { "ip_src_str" => "string" }
       }
       translate {
               field => "ip_dst_str"
               destination => "ip_dst_str"
               override => "true"
               dictionary_path => "/etc/logstash/dictionary/BRANCH-SRV.yaml"
       }
       translate {
               field => "ip_src_str"
               destination => "ip_src_str"
               override => "true"
               dictionary_path => "/etc/logstash/dictionary/BRANCH-SRV.yaml"
       }
}

```

My Dictionary example:  
`"10.0.0.1":SOMEHOSTNAME`

What is the best manner to use dictionary against IP address?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 27, 2016, 5:53am UTC](https://discuss.elastic.co/t/ip-address-and-dictionary-new-field-as-string/61544/2 "2016-09-27T05:53:36Z")

</div>

There's no IP address type inside Logstash. IP addresses are stored as strings so there's no need to convert anything.

Your unspecified problem is most likely caused by your incorrect assumption that the mutate options apply in the order they're listed. See [https://github.com/logstash-plugins/logstash-filter-mutate/issues/27](https://github.com/logstash-plugins/logstash-filter-mutate/issues/27).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:36am UTC](https://discuss.elastic.co/t/ip-address-and-dictionary-new-field-as-string/61544/3 "2017-07-06T04:36:45Z")

</div>


