# Looukps with memcahed or tanslate filter

**URL:** <https://discuss.elastic.co/t/looukps-with-memcahed-or-tanslate-filter/310650>\
**Category:** Logstash\
**Created:** [July 26, 2022, 2:11pm UTC](https://discuss.elastic.co/t/looukps-with-memcahed-or-tanslate-filter/310650 "2022-07-26T14:11:38Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![paulohperes](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paulohperes/32/107556_2.png) [@paulohperes](https://discuss.elastic.co/u/paulohperes)\
**Post date:** [July 26, 2022, 2:11pm UTC](https://discuss.elastic.co/t/looukps-with-memcahed-or-tanslate-filter/310650/1 "2022-07-26T14:11:38Z")

</div>

Hi,

I am doubt about lookups. Recently I implemented a pipeline using the filter plugin Memcached, but the Memcached plugin does not work well with json values. I needed to do this for work:

```auto
memcached {
        hosts => ["localhost"]
        get => {
            "%{ip}" => "[host_detail_tmp]"
        }
        add_tag => "key_founded"        
    }

    if "key_founded" in [tags] {
        dissect {
            mapping => {
                "host_detail_tmp" => "%{hostname}::%{type}::%{vendor}::%{model}"
            }
        }
    }

```

The filter plugin translate looks better with json values. I choose Memcached because I need to keep keys always updated.

For performance, wich filter is better? And, how can I keep updated json file using translate plugin?

tks.

Paulo

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 26, 2022, 2:43pm UTC](https://discuss.elastic.co/t/looukps-with-memcahed-or-tanslate-filter/310650/2 "2022-07-26T14:43:39Z")

</div>

You can keep your keys updated with the `translate` filter as well, you need to point to a file with your external dictionary and set a refresh interval and logstash will update the values and keys if they change.

If you want an example, I made a [blog post](http://web.leandrojmp.com/posts/en/2021/02/logstash-translate) about the translate filter a couple of time ago.

About the performance, both are pretty fast, but since the `translate` filter looks for the key-value pairs in the memory of the logstash process, it will be a little faster, but it has some limitations about the size of the dictionary.

In this case I also made an [old blog post](http://web.leandrojmp.com/posts/en/2021/04/logstash-memcached) about some differences between translate and memcached.

The main advantaged is that you can have larger dictionaries in memcached and multiple logstash can connect to it if needed.

If your memcached is in the same host of your logstash, you could also configure it to listen to a unix socket and configure the filter to connect to the unix socket, while this is not in the documentation, but it works. I made a [PR](https://github.com/logstash-plugins/logstash-filter-memcached/pull/31) to add this in the documentation, but it is still waiting a review from someone at elastic.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2022, 2:44pm UTC](https://discuss.elastic.co/t/looukps-with-memcahed-or-tanslate-filter/310650/3 "2022-08-23T14:44:15Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
