# Logstash Netflow translate and convert a field

**URL:** <https://discuss.elastic.co/t/logstash-netflow-translate-and-convert-a-field/90173>\
**Category:** Logstash\
**Created:** [June 20, 2017, 11:46pm UTC](https://discuss.elastic.co/t/logstash-netflow-translate-and-convert-a-field/90173 "2017-06-20T23:46:03Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [June 20, 2017, 11:46pm UTC](https://discuss.elastic.co/t/logstash-netflow-translate-and-convert-a-field/90173/1 "2017-06-20T23:46:03Z")

</div>

Hi there,  
I'm trying to add extra information to my netflow field, more specifically netflow.direction

Currently it uses number format but I would like it to be a string as I'm adding a string

I've ended up doing this and its working if I output to file

if [type] == "netflow" {  
translate {  
field =\> "[netflow][direction]"  
destination =\> "[netflow][direction]"  
override =\> "true"  
dictionary =\> ["0", "0-Ingress", "1", "1-Egress"]  
}

However, in elasticsearch netflow.direction is a number so I get this error in logstash

`[2017-06-21T09:39:07,764][WARN][logstash.outputs.elasticsearch] Could not index event to Elasticsearch. {:status=>400, :action=>["index", {:_id=>nil, :_index=>"logstash-2017.06.20", :_type=>"netflow", :_routing=>nil}, 2017-06-20T23:38:39.000Z 192.168.199.1 %{message}], :response=>{"index"=>{"_index"=>"logstash-2017.06.20", "_type"=>"netflow", "_id"=>"AVzH37xKAPHi6zTnNzhA", "status"=>400, "error"=>{"type"=>"mapper_parsing_exception", "reason"=>"failed to parse [netflow.direction]", "caused_by"=>{"type"=>"number_format_exception", "reason"=>"For input string: \"1-Egress\""}}}}}`

What's the best way to do this, I've tried using convert but not having much luck  
mutate {  
convert =\> { "[netflow][direction]" =\> "string"}  
}

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [June 21, 2017, 12:24am UTC](https://discuss.elastic.co/t/logstash-netflow-translate-and-convert-a-field/90173/2 "2017-06-21T00:24:20Z")

</div>

The issue is on Elasticsearch side. The mapping used there is already considering the field `direction` as a number. I recommend that you keep it that way and create another field (i.e. `direction_description`) for the `Ingress/Egress` value

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [June 21, 2017, 1:15am UTC](https://discuss.elastic.co/t/logstash-netflow-translate-and-convert-a-field/90173/3 "2017-06-21T01:15:20Z")

</div>

Thanks for your reply. Could you give me an example, I've just started using the filters

---

<div class="post-metadata">

**Author:** ![thiago](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/thiago/32/32096_2.png) [@thiago](https://discuss.elastic.co/u/thiago)\
**Post date:** [June 21, 2017, 1:19am UTC](https://discuss.elastic.co/t/logstash-netflow-translate-and-convert-a-field/90173/4 "2017-06-21T01:19:30Z")

</div>

Use the same translate filter, but change `destination` to something like `destination => "[netflow][direction_description]"`. Also change the dictionary so it translates to `Ingress/Egress` instead of `0-Ingress/1-Egress`.

---

<div class="post-metadata">

**Author:** ![VamPikmin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vampikmin/32/22367_2.png) [@VamPikmin](https://discuss.elastic.co/u/VamPikmin)\
**Post date:** [June 21, 2017, 1:22am UTC](https://discuss.elastic.co/t/logstash-netflow-translate-and-convert-a-field/90173/5 "2017-06-21T01:22:12Z")

</div>

Thanks Thiago, that worked like a charm

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 19, 2017, 1:22am UTC](https://discuss.elastic.co/t/logstash-netflow-translate-and-convert-a-field/90173/6 "2017-07-19T01:22:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
