# Logstash refference condition

**URL:** <https://discuss.elastic.co/t/logstash-refference-condition/168159>\
**Category:** Logstash\
**Created:** [February 13, 2019, 7:23am UTC](https://discuss.elastic.co/t/logstash-refference-condition/168159 "2019-02-13T07:23:56Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![fadihaddad](https://avatars.discourse-cdn.com/v4/letter/f/4bbf92/32.png) [@fadihaddad](https://discuss.elastic.co/u/fadihaddad)\
**Post date:** [February 13, 2019, 7:23am UTC](https://discuss.elastic.co/t/logstash-refference-condition/168159/1 "2019-02-13T07:23:57Z")

</div>

well let me tell you my case so i can simplify everything so I have 2 csv files reference\_1.csv and reference\_2.csv  
plus the one I am indexing

I have 2 fields test1 and test2

test1 has {  
"test1\_ID": "123"  
etc  
}

test2 is  
test2{  
"test2\_name": "name"  
etc  
}  
the reference\_2.csv has  
test1\_id test2\_name Description code\_name  
12 name1 xxxx xxxx  
12 name2 xxxx xxxx  
13 name1 xxxx xxxx  
13 name2 xxxx xxxx  
I want to check if test1\_id is available in reference\_2 than I reference to it else I reference to reference\_1

then I want to use test1\_id and test2\_name as keys to take code\_name  
so I get

test1{  
"test1\_ID": "123"  
"code\_name": "codename"  
etc  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 13, 2019, 2:34pm UTC](https://discuss.elastic.co/t/logstash-refference-condition/168159/2 "2019-02-13T14:34:01Z")

</div>

One way to do this is to transform reference\_2.csv into something that a translate filter can use. Suppose we start off with

```auto
col1,col2,"Other","Stuff"
3,255,Lorem ipsum dolor sit amet,consectetur adipiscing elit
2,256,sed do eiusmod tempor incididunt,ut labore et dolore magna aliqua

```

and we run it through a configuration like this

```
input { stdin {} }
filter {
    csv { autodetect_column_names => true target => "object" }
    mutate { rename => { "[object][col2]" => "[key]" } }
}
output { stdout { codec => line { format => '"%{key}": %{object}' } } }

```

using

```
/usr/share/logstash/bin/logstash -f /path/to/file.conf --path.settings /etc/logstash < lookup.csv > dictionary.yml

```

that gets you a file that looks like this

```auto
"255": {"Stuff":"consectetur adipiscing elit","Other":"Lorem ipsum dolor sit amet","col1":"3"}
"256": {"Stuff":"ut labore et dolore magna aliqua","Other":"sed do eiusmod tempor incididunt","col1":"2"}

```

Note that we are not using numeric keys, we are converting them to strings.

If you then configure a translate filter to use that then it looks up the string "255" (since add\_field always adds strings, not integers) and parses the JSON for you

```
    mutate { add_field => { "key" => 255 } }
    translate { dictionary_path => "/home/user/dictionary.yml" field => "key" destination => "[@metadata][dict]" }
    mutate { add_field => { "stuff" => "%{[@metadata][dict][Stuff]}" } }

```

results in

```
 "@metadata" => {
    "dict" => {
        "Other" => "Lorem ipsum dolor sit amet",
         "col1" => "3",
        "Stuff" => "consectetur adipiscing elit"
    }
},
       "key" => "255",
     "stuff" => "consectetur adipiscing elit"

```

There is another way to do this, which I am still thinking about, but this would work.

---

<div class="post-metadata">

**Author:** ![fadihaddad](https://avatars.discourse-cdn.com/v4/letter/f/4bbf92/32.png) [@fadihaddad](https://discuss.elastic.co/u/fadihaddad)\
**Post date:** [February 18, 2019, 9:27am UTC](https://discuss.elastic.co/t/logstash-refference-condition/168159/4 "2019-02-18T09:27:17Z")

</div>

I got a little lost here, is there a way we can use hash of ruby for something simpler because both my test1\_ID and test2\_name are nested fields and like test1 feild has

test1 {

test\_ID  
test\_before  
test\_after  
}

I want to add a column from the csv file called code\_name which has the 2 nested fields test1\_ID and test2\_name as a key so that the field becomes  
test1 {  
code\_name  
test\_ID  
test\_before  
test\_after  
}  
and running logstash as a service cannot allow me to enter manual commands everytime

---

<div class="post-metadata">

**Author:** ![fadihaddad](https://avatars.discourse-cdn.com/v4/letter/f/4bbf92/32.png) [@fadihaddad](https://discuss.elastic.co/u/fadihaddad)\
**Post date:** [February 19, 2019, 8:24am UTC](https://discuss.elastic.co/t/logstash-refference-condition/168159/5 "2019-02-19T08:24:38Z")

</div>

sorry for bothering you much but can you please help me with this problem

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 19, 2019, 1:21pm UTC](https://discuss.elastic.co/t/logstash-refference-condition/168159/6 "2019-02-19T13:21:01Z")

</div>

If you cannot transform the data into something that a translate filter could use then you could implement all of the logic in ruby.

---

<div class="post-metadata">

**Author:** ![fadihaddad](https://avatars.discourse-cdn.com/v4/letter/f/4bbf92/32.png) [@fadihaddad](https://discuss.elastic.co/u/fadihaddad)\
**Post date:** [February 19, 2019, 1:22pm UTC](https://discuss.elastic.co/t/logstash-refference-condition/168159/7 "2019-02-19T13:22:13Z")

</div>

well I'm not good at ruby can you tell me how

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 19, 2019, 1:22pm UTC](https://discuss.elastic.co/t/logstash-refference-condition/168159/8 "2019-03-19T13:22:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
