# Logstash ip protocol enriching

**URL:** <https://discuss.elastic.co/t/logstash-ip-protocol-enriching/281496>\
**Category:** Logstash\
**Created:** [August 16, 2021, 3:32am UTC](https://discuss.elastic.co/t/logstash-ip-protocol-enriching/281496 "2021-08-16T03:32:27Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ThreatInter](https://avatars.discourse-cdn.com/v4/letter/t/49beb7/32.png) [@ThreatInter](https://discuss.elastic.co/u/ThreatInter)\
**Post date:** [August 16, 2021, 3:32am UTC](https://discuss.elastic.co/t/logstash-ip-protocol-enriching/281496/1 "2021-08-16T03:32:28Z")

</div>

Hello community. I was busy with the task of collecting netflow using logstash. So I noticed that the netflow data after the "netflow" codec contains the "protocol" field, which is actually the protocol number. But there is no filter in logstash that can convert the protocol number to the name of the protocol. Why is that? How do you deal with this task? How about adding a filter that will do this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 16, 2021, 2:42pm UTC](https://discuss.elastic.co/t/logstash-ip-protocol-enriching/281496/2 "2021-08-16T14:42:42Z")

</div>

You could use a [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) filter to do that.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [August 16, 2021, 3:07pm UTC](https://discuss.elastic.co/t/logstash-ip-protocol-enriching/281496/3 "2021-08-16T15:07:42Z")

</div>

As badger said, you can do that using the translate filter.

I use the following configuration in some pipelines I have:

```auto
    translate {
        field => "proto"
        destination => "[network][protocol]"
        dictionary => {
            "6" => "TCP"
            "17" => "UDP"
            "1" => "ICMP"
        }
        remove_field => ["proto"]
    }

```

You can get the list of protocol numbers [here](https://www.iana.org/assignments/protocol-numbers/protocol-numbers.xhtml).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 13, 2021, 3:08pm UTC](https://discuss.elastic.co/t/logstash-ip-protocol-enriching/281496/4 "2021-09-13T15:08:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
