# Logstash field matching

**URL:** <https://discuss.elastic.co/t/logstash-field-matching/51791>\
**Category:** Logstash\
**Created:** [June 3, 2016, 11:19am UTC](https://discuss.elastic.co/t/logstash-field-matching/51791 "2016-06-03T11:19:24Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Kishore](https://avatars.discourse-cdn.com/v4/letter/k/8edcca/32.png) [@Kishore](https://discuss.elastic.co/u/Kishore)\
**Post date:** [June 3, 2016, 11:19am UTC](https://discuss.elastic.co/t/logstash-field-matching/51791/1 "2016-06-03T11:19:25Z")

</div>

I want to use one of the field from the following output in translate filter.  
Below is the output looks like.

{  
"message" =\> "May 19 08:27:11 ip-21-54-0-85 openvpn[20191]: kishore.uppala/1.184.195.114:36389 MULTI\_sva: pool returned IPv4=12.24.254.14, IPv6=(Not enabled)",  
"@version" =\> "1",  
"@timestamp" =\> "2016-06-03T11:06:08.844Z",  
"host" =\> "ip-21-54-233-31.ec2.internal",  
"tags" =\> [  
[0] "GeoIP"  
],  
"vpc\_id" =\> "vpc-87377fe2",  
"region\_id" =\> "US East (N. Virginia)",  
"cust\_id" =\> "ACN",  
"month" =\> "May",  
"day" =\> "19",  
"time" =\> "08:27:11",  
"hostname" =\> "ip-10-254-0-85",  
"vpn\_daemon" =\> "openvpn",  
"vpn\_id" =\> "20191",  
"username" =\> "kishore.uppala",  
"public\_ip" =\> "1.184.195.114",  
"publicip\_port" =\> "36389",  
"vpn\_status" =\> "pool returned",  
"vpn\_ip" =\> "12.24.254.14",  
"vpn\_msg" =\> "(Not enabled)",  
"received\_at" =\> "2016-06-03T11:06:08.844Z",  
"received\_from" =\> "ip-21-54-233-31.ec2.internal",  
"geoip" =\> {  
"ip" =\> "1.184.195.114",  
"country\_code2" =\> "CN",  
"country\_code3" =\> "CHN",  
"country\_name" =\> "China",  
"continent\_code" =\> "AS",  
"region\_name" =\> "30",  
"city\_name" =\> "Guangzhou",  
"latitude" =\> 23.11670000000001,  
"longitude" =\> 113.25,  
"timezone" =\> "Asia/Chongqing",  
"real\_region\_name" =\> "Guangdong",  
"location" =\> [  
[0] 113.25,  
[1] 23.11670000000001  
],  
"coordinates" =\> [  
[0] 113.25,  
[1] 23.11670000000001  
]  
}  
}

I want to match the field 'country\_name' from above output with malicious country list. but unable to query using below field option. ( i have tried with field =\> "country\_name" also )

translate {  
**field =\> "geoip.country\_name"**  
destination =\> "country"  
dictionary\_path =\> "/home/ec2-user/malicious"  
add\_tag =\> ["Malicious"]  
}

Kindly help me on this.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 3, 2016, 11:21am UTC](https://discuss.elastic.co/t/logstash-field-matching/51791/2 "2016-06-03T11:21:59Z")

</div>

> ```
> field => "geoip.country_name"
> 
> ```

Use `[geoip][country_name]`. See [Accessing event data and fields | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html#logstash-config-field-references).

---

<div class="post-metadata">

**Author:** ![Kishore](https://avatars.discourse-cdn.com/v4/letter/k/8edcca/32.png) [@Kishore](https://discuss.elastic.co/u/Kishore)\
**Post date:** [June 3, 2016, 11:24am UTC](https://discuss.elastic.co/t/logstash-field-matching/51791/3 "2016-06-03T11:24:02Z")

</div>

> [@magnusbaeck](#):
>
> [geoip][country\_name]

Thanks a lot Magnus, it is working. I have been working for 2 hrs to fix this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:54am UTC](https://discuss.elastic.co/t/logstash-field-matching/51791/4 "2017-07-06T04:54:36Z")

</div>


