# Match and replace in logstash

**URL:** <https://discuss.elastic.co/t/match-and-replace-in-logstash/316406>\
**Category:** Logstash\
**Created:** [October 12, 2022, 7:15am UTC](https://discuss.elastic.co/t/match-and-replace-in-logstash/316406 "2022-10-12T07:15:52Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![tegerei](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tegerei/32/132992_2.png) [@tegerei](https://discuss.elastic.co/u/tegerei)\
**Post date:** [October 12, 2022, 7:15am UTC](https://discuss.elastic.co/t/match-and-replace-in-logstash/316406/1 "2022-10-12T07:15:52Z")

</div>

Hello,  
I have a setup where I collect PfSense VPN logs and pass them through Logstash to extract some fields. My VPN logs have LDAP usernames such as **doejo** , which implies the full name of John Doe. Now I need the logs having doejo to be translated to John Doe (if possible in Logstash) so that it is displayed as the full name on the index in Kibana.

Thank you.

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [October 12, 2022, 7:21am UTC](https://discuss.elastic.co/t/match-and-replace-in-logstash/316406/2 "2022-10-12T07:21:54Z")

</div>

You want to read logs, get username, do LDAP lookup, replace with full name and save in Elasticsearch?

Check [ldap plugin](https://github.com/Transrian/logstash-filter-ldap)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2022, 7:22am UTC](https://discuss.elastic.co/t/match-and-replace-in-logstash/316406/3 "2022-11-09T07:22:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
