# Logstash Translate filter plugin based on multilevel dictionary

**URL:** <https://discuss.elastic.co/t/logstash-translate-filter-plugin-based-on-multilevel-dictionary/311105>\
**Category:** Logstash\
**Created:** [August 1, 2022, 10:50am UTC](https://discuss.elastic.co/t/logstash-translate-filter-plugin-based-on-multilevel-dictionary/311105 "2022-08-01T10:50:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![who](https://avatars.discourse-cdn.com/v4/letter/w/cdc98d/32.png) [@who](https://discuss.elastic.co/u/who)\
**Post date:** [August 1, 2022, 10:50am UTC](https://discuss.elastic.co/t/logstash-translate-filter-plugin-based-on-multilevel-dictionary/311105/1 "2022-08-01T10:50:01Z")

</div>

Assuming we have a dictionary with nested structure (YAML):

```
"key1":
  "sub-key1": "value1"
  "sub-key2": "value2"
  "sub-key3": "value3"
"key2":
  "sub-key4": "value4"
  "sub-key5": "value5"
  "sub-key6": "value6"

```

Currently, the below `translate` plugin configuration gives an object with all "sub-key"s as translated value:

```
 translate {
    source => "[field1]"
    target => "[translatedField]"
    dictionary_path => "/path/to/dictionary.yaml"
  }

```

The equivalent phrase of "sub-key1" is in another event field (i.e. `field2`). However I couldn't utilize it with something like `source => "[field1][%{field2}]"` or `source => "[field1][field2]` in `translate` plugin.

Current result:

```
"translatedField" => {
    "sub-key1" => "value1"
    "sub-key2" => "value2"
    "sub-key3" => "value3"
}

```

while the desired result is:

```
"translatedField" => "value1"

```

What's the efficient way to access the values as the final translation? (preferably with just one `translate` plugin usage).  
A workaround would be making a flatted dictionary with the "key" prefixed to all sub-keys and then using a temporary field for source like this ([source](https://discuss.elastic.co/t/how-to-reference-value-of-field-in-translate/207561/16)):

```
translate {
    add_field => { "lookup" => "%{field1}_%{field2}" }
    source => "lookup"
    target => "translatedField"
    dictionary_path => "/path/to/dictionary.yaml"
    remove_field => ["lookup"]
}

```

Anyway, the above config won't work apparently; because `add_field` acts when the `translate` filter is successful (according to [documentation](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-add_field)) so `add_field` should be used in a previous filter. After all, I'm looking for a more elegant way.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2022, 10:50am UTC](https://discuss.elastic.co/t/logstash-translate-filter-plugin-based-on-multilevel-dictionary/311105/2 "2022-08-29T10:50:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
