# Logstash add field based on external source

**URL:** <https://discuss.elastic.co/t/logstash-add-field-based-on-external-source/245236>\
**Category:** Logstash\
**Created:** [August 17, 2020, 12:38pm UTC](https://discuss.elastic.co/t/logstash-add-field-based-on-external-source/245236 "2020-08-17T12:38:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mohammad\_Mousavi](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mohammad_mousavi/32/56508_2.png) [@Mohammad\_Mousavi](https://discuss.elastic.co/u/Mohammad_Mousavi)\
**Post date:** [August 17, 2020, 12:38pm UTC](https://discuss.elastic.co/t/logstash-add-field-based-on-external-source/245236/1 "2020-08-17T12:38:27Z")

</div>

Hi, I have a stream server. I store the logs on elasticsearch. The stream server's log contain requested urls from clients. The logs are similar to nginx logs but with more fields. one of the query params in the url is "product id". Every product has unique id in mysql database.  
My problem is that when I create charts on kibana, I use these products IDs and I have to query mysql to find out what are the names of most visited products.  
Is there any solution that I be able to use some text or csv file or even connect to that specific mysql table to add an extra field in logstash ?  
I know there is some plugin like ip2location which can use local binary database, maybe I should build some database like that ... I have no idea... but the scenario is similar ... the input is some field and plugin ( ip2location ) add more fields based on input field.  
Anyone had any experience ?  
sorry for my English.  
Thanx a lot

---

<div class="post-metadata">

**Author:** ![Jenni](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jenni/32/29684_2.png) [@Jenni](https://discuss.elastic.co/u/Jenni)\
**Post date:** [August 17, 2020, 12:43pm UTC](https://discuss.elastic.co/t/logstash-add-field-based-on-external-source/245236/2 "2020-08-17T12:43:45Z")

</div>

You can use [Jdbc\_streaming](https://www.elastic.co/guide/en/logstash/current/plugins-filters-jdbc_streaming.html) or [Jdbc\_static](https://www.elastic.co/guide/en/logstash/current/plugins-filters-jdbc_static.html) for that. (The latter might fit your purpose better, if your product names don't change frequently.)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 17, 2020, 1:57pm UTC](https://discuss.elastic.co/t/logstash-add-field-based-on-external-source/245236/3 "2020-08-17T13:57:04Z")

</div>

If you have a CSV file then a translate filter would also be an option.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2020, 3:17pm UTC](https://discuss.elastic.co/t/logstash-add-field-based-on-external-source/245236/5 "2020-09-14T15:17:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
