# Logstash Translate Dictionary not working

**URL:** <https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420>\
**Category:** Logstash\
**Created:** [May 19, 2020, 11:03pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420 "2020-05-19T23:03:10Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![AliMalik](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@AliMalik](https://discuss.elastic.co/u/AliMalik)\
**Post date:** [May 19, 2020, 11:03pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/1 "2020-05-19T23:03:11Z")

</div>

Hi All, I need some help. I am trying to use a translate filter in logstash to translate winlog.event\_data.AccessList value to some meaningful field but it's not working. below is my code in the filter file.  
Looks like this if statement "if "AccessList" in [event\_date]" is not working. I tried `[winlog][even_data] and `[winlog.event\_data] but still doesn't work.

```auto
filter {
 if "fileserver" in [tags] {
   if "AccessList" in [event_data] {
    mutate{
           add_field => { "TestField" => "Testing" }
    }
    translate {
      field => "AccessList"
      destination => "Accesses"
      exact => false
      dictionary => [ '%%1537', "Delete",
                      '%%1538', "ReadControl",
                      '%%1539', "ReadControl",
                      '%%1540', "ReadControl",
                      '%%1541', "Synchronize",
                      '%%1542', "Synchronize",
                      '%%4416', "ReadData",
                      '%%4417', "WriteData",
                      '%%4418', "AppendData",
                      '%%4419', "ReadEA",
                      '%%4420', "WriteEA",
                      '%%4423', "ReadAttrib",
                      '%%4424', "WriteAttrib",
                      '%%1801', "Granted",
                      '%%1805', "NotGranted" ]
    }
   }
  }
}

```

---

<div class="post-metadata">

**Author:** ![andres-perez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andres-perez/32/136461_2.png) [@andres-perez](https://discuss.elastic.co/u/andres-perez)\
**Post date:** [May 20, 2020, 3:32pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/2 "2020-05-20T15:32:19Z")

</div>

Hi,  
Logstash uses bracket notation for fields: [https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html](https://www.elastic.co/guide/en/logstash/current/event-dependent-configuration.html)

If you want to check if "winlog.event\_data.AccessList" field exists, you must use the condition:

```auto
if [winlog][event_data][AccessList] {

```

---

<div class="post-metadata">

**Author:** ![AliMalik](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@AliMalik](https://discuss.elastic.co/u/AliMalik)\
**Post date:** [May 20, 2020, 9:01pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/3 "2020-05-20T21:01:41Z")

</div>

Thanks Andres, I have tried this as well but no luck ☹

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 20, 2020, 9:03pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/4 "2020-05-20T21:03:43Z")

</div>

If you add

```
output { stdout { codec => rubydebug } }

```

what does an event look like? Also what does your modified configuration look like?

---

<div class="post-metadata">

**Author:** ![AliMalik](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@AliMalik](https://discuss.elastic.co/u/AliMalik)\
**Post date:** [May 20, 2020, 9:04pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/5 "2020-05-20T21:04:53Z")

</div>

give me sec I will try this. I tried using mutate and added a field before this if condition, also i removed if condition but still dictionary didn't work.

---

<div class="post-metadata">

**Author:** ![AliMalik](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@AliMalik](https://discuss.elastic.co/u/AliMalik)\
**Post date:** [May 20, 2020, 9:10pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/6 "2020-05-20T21:10:15Z")

</div>

Below is the config file but with added output tag logstash service not starting.  
Failed to execute action {:action=\>LogStash::PipelineAction::Create/pipeline\_id:main, :excep...after filter...

```auto
filter {
 if "fileserver" in [tags] and [event_id] == 4663 {
   if [winlog][event_data][AccessList] {
    mutate{
           add_field => { "QaisarAli" => "Testing" }
    }
    translate {
      field => "[winlog][event_data][AccessList]"
      destination => "[ActionTaken]"
      exact => false
      dictionary => [ '%%1537', "Delete",
                      '%%1538', "ReadControl",
                      '%%1539', "ReadControl",
                      '%%1540', "ReadControl",
                      '%%1541', "Synchronize",
                      '%%1542', "Synchronize",
                      '%%4416', "ReadData",
                      '%%4417', "WriteData",
                      '%%4418', "AppendData",
                      '%%4419', "ReadEA",
                      '%%4420', "WriteEA",
                      '%%4423', "ReadAttrib",
                      '%%4424', "WriteAttrib",
                      '%%1801', "Granted",
                      '%%1805', "NotGranted" ]
    }
   }
  }
output { stdout { codec => rubydebug } }
}

```

---

<div class="post-metadata">

**Author:** ![AliMalik](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@AliMalik](https://discuss.elastic.co/u/AliMalik)\
**Post date:** [May 20, 2020, 9:12pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/7 "2020-05-20T21:12:52Z")

</div>

sorry i added output on wrong spot, now added outside filter tag when checking the status of logstash it shows log fields. and in discovery i can't see that field that I am adding for Testing. which means that if condition is still not checking.

---

<div class="post-metadata">

**Author:** ![AliMalik](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@AliMalik](https://discuss.elastic.co/u/AliMalik)\
**Post date:** [May 20, 2020, 9:17pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/8 "2020-05-20T21:17:48Z")

</div>

and in discovery i can't see that field that I am adding for Testing. which means that if condition is still not checking.

---

<div class="post-metadata">

**Author:** ![AliMalik](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@AliMalik](https://discuss.elastic.co/u/AliMalik)\
**Post date:** [May 20, 2020, 9:35pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/9 "2020-05-20T21:35:17Z")

</div>

```auto
# /usr/share/logstash/bin/logstash -f 12-fileaccess-filter.conf
WARNING: Could not find logstash.yml which is typically located in $LS_HOME/config or /etc/logstash. You can specify the path using --path.settings. Continuing using the defaults
Could not find log4j2 configuration at path /usr/share/logstash/config/log4j2.properties. Using default config which logs errors to the console
[WARN] 2020-05-21 07:33:29.522 [LogStash::Runner] multilocal - Ignoring the 'pipelines.yml' file because modules or command line options are specified
[INFO] 2020-05-21 07:33:29.533 [LogStash::Runner] runner - Starting Logstash {"logstash.version"=>"7.6.2"}
[INFO] 2020-05-21 07:33:32.769 [Converge PipelineAction::Create<main>] Reflections - Reflections took 42 ms to scan 1 urls, producing 20 keys and 40 values
[WARN] 2020-05-21 07:33:34.611 [[main]-pipeline-manager] LazyDelegatingGauge - A gauge metric of an unknown type (org.jruby.RubyArray) has been created for key: cluster_uuids. This may result in invalid serialization. It is recommended to log an issue to the responsible developer/development team.
[INFO] 2020-05-21 07:33:34.616 [[main]-pipeline-manager] javapipeline - Starting pipeline {:pipeline_id=>"main", "pipeline.workers"=>4, "pipeline.batch.size"=>125, "pipeline.batch.delay"=>50, "pipeline.max_inflight"=>500, "pipeline.sources"=>["/etc/logstash/conf.d/12-fileaccess-filter.conf"], :thread=>"#<Thread:0x77ae9b26 run>"}
[INFO] 2020-05-21 07:33:35.697 [[main]-pipeline-manager] javapipeline - Pipeline started {"pipeline.id"=>"main"}
[INFO] 2020-05-21 07:33:35.762 [Agent thread] agent - Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
[INFO] 2020-05-21 07:33:36.032 [Api Webserver] agent - Successfully started Logstash API endpoint {:port=>9600}
[INFO] 2020-05-21 07:33:36.389 [LogStash::Runner] runner - Logstash shut down.

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 20, 2020, 10:03pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/10 "2020-05-20T22:03:16Z")

</div>

It would be really helpful to see an event output by

```
output { stdout { codec => rubydebug } }

```

That will allow us to confirm that the field has the name you think it has, that [event\_id] is numeric, and not a string, and that "fileserver" is in [tags].

---

<div class="post-metadata">

**Author:** ![AliMalik](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@AliMalik](https://discuss.elastic.co/u/AliMalik)\
**Post date:** [May 20, 2020, 10:17pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/11 "2020-05-20T22:17:50Z")

</div>

```auto
"tags" => [
[0] "eventlog",
[1] "fileserver",
[2] "lmfileserver",
[3] "beats_input_codec_plain_applied"
],
"agent" => {
"ephemeral_id" => "b5f0777f-b027-48bd-989f-08615a66f373",
"type" => "winlogbeat",
"hostname" => "LMFILESERVER",
"version" => "7.6.2",
"id" => "f992d4c6-0696-4d16-81de-7752cd2d31c7"
},
"ecs" => {
"version" => "1.4.0"
},
"winlog" => {
"api" => "wineventlog",
"keywords" => [
[0] "Audit Success"
],
"task" => "File System",
"channel" => "Security",
"event_data" => {
"ObjectServer" => "Security",
"ResourceAttributes" => "S:AI",
"SubjectUserName" => "vtay",
"ObjectName" => "\\Device\\HarddiskVolume7\\Share\\Text\\Business Management System",
"SubjectLogonId" => "0x21296c18",
"HandleId" => "0x1648",
"AccessMask" => "0x20000",
"ProcessId" => "0x4",
"AccessList" => "%%1538\n\t\t\t\t",
"ObjectType" => "File",
"SubjectDomainName" => "WEBVIOUS",
"SubjectUserSid" => "S-1-5-21-1234567897-1234567897-3126549871-1759"
},
"provider_name" => "Microsoft-Windows-Security-Auditing",
"version" => 1,
"process" => {
"pid" => 4,
"thread" => {
"id" => 1804
}
},
"event_id" => 4663,
"computer_name" => "fileserver.webvious.com.au",
"provider_guid" => "{54849625-5478-4994-a5ba-3e3b0328c30d}",
"record_id" => 42186209,
"opcode" => "Info"
},
"@timestamp" => 2020-05-20T03:03:09.967Z,
"event" => {
"created" => "2020-05-20T22:11:23.536Z",
"code" => 4663,
"action" => "File System",
"provider" => "Microsoft-Windows-Security-Auditing",
"kind" => "event"
},
"@version" => "1"
}
{
"host" => {
"architecture" => "x86_64",
"name" => "fileserver.webvious.com.au",
"hostname" => "LMFILESERVER",
"os" => {
"platform" => "windows",
"name" => "Windows Server 2019 Standard",
"version" => "10.0",
"build" => "17763.1158",
"family" => "windows",
"kernel" => "10.0.17763.1158 (WinBuild.160101.0800)"
},

```

---

<div class="post-metadata">

**Author:** ![AliMalik](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@AliMalik](https://discuss.elastic.co/u/AliMalik)\
**Post date:** [May 20, 2020, 10:28pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/12 "2020-05-20T22:28:40Z")

</div>

```auto
if i only checkt his if "fileserver" in [tags] then it goes to second line if it finds fileserver in tags but when i type this if "fileserver" in [tags] and [winlog][event_id] == "4663" it doesn't do anything so [winlog][event_id] == "4663" doesn't works. i tried removing winlog and removing quotes from 4663 but no luck.

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 20, 2020, 11:17pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/13 "2020-05-20T23:17:13Z")

</div>

```
"event_id" => 4663

```

There are no quotes around event\_id so you should be comparing it to a number, not a string. I would have expected

```
if "fileserver" in [tags] and [winlog][event_id] == 4663 {
    if [winlog][event_data][AccessList] {

```

to result in the code in the if block getting executed.

---

<div class="post-metadata">

**Author:** ![AliMalik](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@AliMalik](https://discuss.elastic.co/u/AliMalik)\
**Post date:** [May 20, 2020, 11:21pm UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/14 "2020-05-20T23:21:34Z")

</div>

Yes Badger i figured it out 10 minutes ago. you are right by using [winlog][event\_id] it worked fine.

Thanks a lot for your help mate.

---

<div class="post-metadata">

**Author:** ![AliMalik](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@AliMalik](https://discuss.elastic.co/u/AliMalik)\
**Post date:** [May 21, 2020, 12:34am UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/15 "2020-05-21T00:34:18Z")

</div>

One more thing, Now as I have got this dictionary working and it's translating event id to eventdescription I can see this EventDesc field in discovery section with a question mark infront of it but i can't use this field in Visualizations. how do i do this?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 21, 2020, 12:57am UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/16 "2020-05-21T00:57:11Z")

</div>

I think that is a kibana question rather than a logstash question, but the answer may be to do a refresh of the fields in the index pattern management page in kibana. I have not run kibana in a long time so I do not recall it very clearly.

---

<div class="post-metadata">

**Author:** ![AliMalik](https://avatars.discourse-cdn.com/v4/letter/a/278dde/32.png) [@AliMalik](https://discuss.elastic.co/u/AliMalik)\
**Post date:** [May 21, 2020, 1:41am UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/17 "2020-05-21T01:41:29Z")

</div>

Badger you are the legend. Got it working now. Thanks a lot

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 18, 2020, 1:50am UTC](https://discuss.elastic.co/t/logstash-translate-dictionary-not-working/233420/18 "2020-06-18T01:50:57Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
