# Mark IP Value with an external list

**URL:** <https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055>\
**Category:** Logstash\
**Created:** [December 14, 2016, 4:50pm UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055 "2016-12-14T16:50:33Z")\
**Posts on this page:** 1\
**Showing post:** 8

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [December 15, 2016, 12:02pm UTC](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055/8 "2016-12-15T12:02:52Z")

</div>

Translate allows you to perform a lookup against a dictionary based on the contents of a field, e.g. `clientip`, and populate a different field with the result, which could be `SECURE` or `MALICIOUS` as in your example. You could combine this with a conditional (the field containing the result of the lookup is not set) and use a mutate filter to then set it to `MALICIOUS`, which would be the default value. This should do what your Ruby filter does but avoid loading the file once for every event.

---

_[View the full topic](https://discuss.elastic.co/t/mark-ip-value-with-an-external-list/69055)._
