# Logstash configuration- How to do dynamic mapping?

**URL:** <https://discuss.elastic.co/t/logstash-configuration-how-to-do-dynamic-mapping/274749>\
**Category:** Logstash\
**Created:** [June 2, 2021, 12:31pm UTC](https://discuss.elastic.co/t/logstash-configuration-how-to-do-dynamic-mapping/274749 "2021-06-02T12:31:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nisha2297](https://avatars.discourse-cdn.com/v4/letter/n/d2c977/32.png) [@Nisha2297](https://discuss.elastic.co/u/Nisha2297)\
**Post date:** [June 2, 2021, 12:31pm UTC](https://discuss.elastic.co/t/logstash-configuration-how-to-do-dynamic-mapping/274749/1 "2021-06-02T12:31:03Z")

</div>

I have one requirement to create dynamic mapping in my Logstash configuration to map two different columns. Please find below details: -  
Below is the ruby code I'm using in my logstash config:

```auto
![image|690x351](upload://r5E8Q9BVhusDRM5TRNVv66mCnHH.png)

In this, I have hardcoded "doc_lob" on the basis of "user". But I have to make this dynamic for "n" number of users to accomodate, so that everytime I don't need to change the code. It can be done by passin the values via an excel sheet or something!

I hope I am clear in explaining my requirement. Can you plz help me with any lead on this?

Thanks,
Nisha

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 2, 2021, 12:33pm UTC](https://discuss.elastic.co/t/logstash-configuration-how-to-do-dynamic-mapping/274749/2 "2021-06-02T12:33:50Z")

</div>

Hello,

It is not clear what you are trying to do, can you share your logstash config using the `</>` code format option? Do not share images.

---

<div class="post-metadata">

**Author:** ![Nisha2297](https://avatars.discourse-cdn.com/v4/letter/n/d2c977/32.png) [@Nisha2297](https://discuss.elastic.co/u/Nisha2297)\
**Post date:** [June 2, 2021, 12:38pm UTC](https://discuss.elastic.co/t/logstash-configuration-how-to-do-dynamic-mapping/274749/3 "2021-06-02T12:38:07Z")

</div>

```auto
I have one requirement to create dynamic mapping in my Logstash configuration to map two different columns. Please find below details: -
Below is the ruby code I'm using in my logstash config:
ruby {
            code =>'table = event.get("[hive][table]");
            user = event.get("[hive][ugi]");
            event.set("[dataconsumption][access_flag]",table);

            if(user == "biuser@NPRD.BIGD.BE")
                event.set("[dataconsumption][doc_lob]","Data & Analytics");

            elsif(user == "hive/nprd.bigd.BE")
                event.set("[dataconsumption][doc_lob]","Marketing Automation");

            elsif(user == "hue/el755.nprd.bigd.be")
                event.set("[dataconsumption][doc_lob]","Analytics Boost");

            elsif(user == "impala.nprd.bigd.BE")
                event.set("[dataconsumption][doc_lob]","Business insights");

            elsif(user == "bhdg@PROD.BE")
                event.set("[dataconsumption][doc_lob]","Product & network Intelligence");
			else
                event.set("[dataconsumption][doc_lob]","Others");
            end'
	}
	
In this, I have hardcoded "doc_lob" on the basis of "user". But I have to make this dynamic for "n" number of users to accomodate, so that everytime I don't need to change the code. It can be done by passin the values via an excel sheet or something!

I hope I am clear in explaining my requirement. Can you plz help me with any lead on this?

Thanks,
Nisha

```

---

<div class="post-metadata">

**Author:** ![Nisha2297](https://avatars.discourse-cdn.com/v4/letter/n/d2c977/32.png) [@Nisha2297](https://discuss.elastic.co/u/Nisha2297)\
**Post date:** [June 3, 2021, 4:34am UTC](https://discuss.elastic.co/t/logstash-configuration-how-to-do-dynamic-mapping/274749/4 "2021-06-03T04:34:04Z")

</div>

@leandrojmp Could you please let me know if this thing(dynamic lookup) is possible in Kibana?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 3, 2021, 3:40pm UTC](https://discuss.elastic.co/t/logstash-configuration-how-to-do-dynamic-mapping/274749/5 "2021-06-03T15:40:56Z")

</div>

If I understood correctly you are trying to populate a field based on the content of another field?

One way to do that in logstash is using the `translate` filter where you would have a dictionary with key-value pairs.

The keys in this dictionary would be the value of the first field, and the value of this dictionary would be the one that you want to populate into the new field.

So, based in your example, you would need a dictionary like this in an external file.

```auto
"biuser@NPRD.BIGD.BE": "Data & Analytics"
"hive/nprd.bigd.BE": "Marketing Automation"
"hue/el755.nprd.bigd.be": "Analytics Boost"
"impala.nprd.bigd.BE": "Business insights"
"bhdg@PROD.BE": "Product & network Intelligence"

```

Then you would need this [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) filter in your pipeline

```auto
translate {
	field => "user"
	destination => "[dataconsumption][doc_lob]"
	dictionary_path => "/path/to/the/dictionary/file.yml"
	refresh_interval => 300
	fallback => "Others"
}

```

What this filter do is check if the value of the `user` field exists as a key in the dictionary file, if it exists, it will get the value for that key and set it as the value of the field `[dataconsumption][doc_lob]`, if it does not exists, it will set the value of the field `[dataconsumption][doc_lob]` as `Others`, because the `fallback` option is set with this value.

For example, if the `user` field has the value `impala.nprd.bigd.BE`, after the event pass through the translate filter, it will have the field `[dataconsumption][doc_lob]` with the value `Business insights`.

You will need to build a process to update the dictionary file, the `refresh_interval` in the filter will tell logstash to check for changes in the file after that interval has passed.

There are other filters that can be used to enrich your data like the [jdbc\_static](https://www.elastic.co/guide/en/logstash/current/plugins-filters-jdbc_static.html) and the [memcached](https://www.elastic.co/guide/en/logstash/current/plugins-filters-memcached.html), but the translate filter is the easiest one to use.

---

<div class="post-metadata">

**Author:** ![Nisha2297](https://avatars.discourse-cdn.com/v4/letter/n/d2c977/32.png) [@Nisha2297](https://discuss.elastic.co/u/Nisha2297)\
**Post date:** [June 4, 2021, 4:16am UTC](https://discuss.elastic.co/t/logstash-configuration-how-to-do-dynamic-mapping/274749/6 "2021-06-04T04:16:13Z")

</div>

Thanks @leandrojmp! Yesterday, I tried Translate only and it served the purpose well.  
Thanks for your reply.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 2, 2021, 4:16am UTC](https://discuss.elastic.co/t/logstash-configuration-how-to-do-dynamic-mapping/274749/7 "2021-07-02T04:16:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
