# \[logstash.filters.jdbc.lookup\] Parameter field not found in event {:lookup\_id=\>

**URL:** <https://discuss.elastic.co/t/logstash-filters-jdbc-lookup-parameter-field-not-found-in-event-lookup-id/169031>\
**Category:** Logstash\
**Created:** [February 19, 2019, 1:50pm UTC](https://discuss.elastic.co/t/logstash-filters-jdbc-lookup-parameter-field-not-found-in-event-lookup-id/169031 "2019-02-19T13:50:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![josep.clavero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josep.clavero/32/41101_2.png) [@josep.clavero](https://discuss.elastic.co/u/josep.clavero)\
**Post date:** [February 19, 2019, 1:50pm UTC](https://discuss.elastic.co/t/logstash-filters-jdbc-lookup-parameter-field-not-found-in-event-lookup-id/169031/1 "2019-02-19T13:50:47Z")

</div>

Hi, I want to enrich some log data with a table in oracle.

[2019-02-19T14:06:29,775][WARN][logstash.filters.jdbc.lookup] Parameter field not found in event {:lookup\_id=\>"local\_integration\_descr", :invalid\_parameters=\>["integrationnorm"]}

When the integrationnorm exist, the query could not be excuted and no values are returned from lookup table.

This is my pipline configuration file:  
input {  
beats {  
port =\> 5044  
host =\> "0.0.0.0"  
}  
}

filter {

```
    grok {
        match => { "message" => "(%{TIMESTAMP_ISO8601:ts}): Information: I-UNK-000-000: (?<tipus_descart>.*). Integration:(?<integrationnorm>.*); Manager:(?<manager>.*); Agent:(?<agent>.*);AlertGroup:(?<alertgroup>.*); AlertKey:(?<alertkey>.*); EMS:(?<ems>.*); Node:(?<node>.*); AlarmedElement:(?<alarmedelement>.*); Summary:(?<summary>.*)"}
    }

    date {
        match => ["ts", "ISO8601"]
        timezone => "Europe/Andorra" 
        remove_field => ["ts"] 
    }

      jdbc_static {
        loaders => [ 
          {
            id => "remote_integration_descr"
            query => "select INTEGRATIONNORM as integrationid, INTEGRATION_NAME as integrationname from NOPUTILITY_INTEGRATION ORDER BY INTEGRATIONNORM"
            local_table => "integration_descr"
          }
        ]
        local_db_objects => [ 
          {
            name => "integration_descr"
            index_columns => ["integrationid"]
            columns => [
              ["integrationid", "varchar(6)"],
              ["integrationname", "varchar(64)"]
            ]
          }
        ]
        local_lookups => [ 
          {
            id => "local_integration_descr"
            query => "select integrationname from integration_descr WHERE integrationid = :id"
            parameters => {id => "[integrationnorm]"}
            target => "integrationlookup"
          }
        ]
        add_field => { integration => "%{[integrationlookup][0][integrationname]}" }
        remove_field => ["integrationlookup"]

        jdbc_user => "ow_impact"
        jdbc_password => "qi0hmh1p"
        jdbc_driver_class => "Java::oracle.jdbc.driver.OracleDriver"
        jdbc_driver_library => "/opt/logstash/lib/ojdbc6.jar"
        jdbc_connection_string => "jdbc:oracle:thin://@(DESCRIPTION = (ADDRESS_LIST = (ADDRESS = (PROTOCOL = TCP)(HOST = oracle-srv-netcool-pd.oracle.sta)(PORT = 1521)))(CONNECT_DATA = (SERVER = DEDICATED)(SERVICE_NAME = SRV_NETCOOL_PD)))"

      }

```

}

output {  
elasticsearch {  
hosts =\> "192.168.80.91:9200"  
index =\> "aes\_netcool-probe-discard-%{+YYYY-MM}"  
}  
}

Thanks

---

<div class="post-metadata">

**Author:** ![josep.clavero](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/josep.clavero/32/41101_2.png) [@josep.clavero](https://discuss.elastic.co/u/josep.clavero)\
**Post date:** [February 20, 2019, 9:42am UTC](https://discuss.elastic.co/t/logstash-filters-jdbc-lookup-parameter-field-not-found-in-event-lookup-id/169031/2 "2019-02-20T09:42:24Z")

</div>

I detected two mistakes:  
I introduce an "if statment" with a regular expression to filter lines that are not a discart in my example and then reduce errors. And the segond is that I change the type of the field and know it works fine.  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 20, 2019, 9:42am UTC](https://discuss.elastic.co/t/logstash-filters-jdbc-lookup-parameter-field-not-found-in-event-lookup-id/169031/3 "2019-03-20T09:42:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
