# Multiple translate filters on the same event field in logstash

**URL:** <https://discuss.elastic.co/t/multiple-translate-filters-on-the-same-event-field-in-logstash/184047>\
**Category:** Logstash\
**Created:** [June 3, 2019, 7:49pm UTC](https://discuss.elastic.co/t/multiple-translate-filters-on-the-same-event-field-in-logstash/184047 "2019-06-03T19:49:15Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![aamirg](https://avatars.discourse-cdn.com/v4/letter/a/f0a364/32.png) [@aamirg](https://discuss.elastic.co/u/aamirg)\
**Post date:** [June 3, 2019, 7:49pm UTC](https://discuss.elastic.co/t/multiple-translate-filters-on-the-same-event-field-in-logstash/184047/1 "2019-06-03T19:49:15Z")

</div>

I am using the following translate filters in my logstash configuration file. I have two separate YAML files that serve as the lookup dictionaries. The logstash event `field` referenced is the same for both filters but their `destination` fields are different. When I execute this, the `destination` field from the first translate filter is populated correctly, but the `destination` filter of the second translate filter fails to populate. How do I ensure that the `destination` of the second field is also populated correctly using these multiple translate filters?

```
translate {
      dictionary_path => "C:/elk/lookupFile_1.yaml"
      field => "eventField_1"
      destination => "destField_1"
}
 
translate {
      dictionary_path => "C:/elk/lookupFile_2.yaml"
      field => "eventField_1"
      destination => "destField_2"
}

```

Two alternatives I think would be possible -

a) Instead of two YAML files, using just one YAML file where the `value` field is an array eg `key1 : val1a ,val1b`. Then using the dissect filter to maybe separate the destination field into separate fields.

b) Create a duplicate of `eventField_1`, say `eventField_1Copy`, and pass that to the field parameter of the second translate filter. I can then drop `eventField_1Copy`

---

<div class="post-metadata">

**Author:** ![pastechecker](https://avatars.discourse-cdn.com/v4/letter/p/0ea827/32.png) [@pastechecker](https://discuss.elastic.co/u/pastechecker)\
**Post date:** [June 4, 2019, 9:20am UTC](https://discuss.elastic.co/t/multiple-translate-filters-on-the-same-event-field-in-logstash/184047/2 "2019-06-04T09:20:29Z")

</div>

The first translate will will clobber the old value of the source field and that is the reason it does not work for the 2nd translate.

If you just have two translations to run, create two duplicates of your field beforehand and use them in the translate "field" section.

You can use the fallback =\> "no match" also to indicate that the translation did not happen for your future logic.

---

<div class="post-metadata">

**Author:** ![aamirg](https://avatars.discourse-cdn.com/v4/letter/a/f0a364/32.png) [@aamirg](https://discuss.elastic.co/u/aamirg)\
**Post date:** [June 5, 2019, 4:33pm UTC](https://discuss.elastic.co/t/multiple-translate-filters-on-the-same-event-field-in-logstash/184047/3 "2019-06-05T16:33:27Z")

</div>

@pastechecker - When you say "clobber the old value of the source field" I am assuming you mean the first translate filter would replace the value of the source field by the corresponding match of the dictionary value. But that wouldn't happen when I create an entirely new destination field in which to store the dictionary value right?

In any case, I was able to get my original configuration working. Turns out the second .yaml lookup file had a formatting issue that I overlooked. Thank you!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 3, 2019, 4:40pm UTC](https://discuss.elastic.co/t/multiple-translate-filters-on-the-same-event-field-in-logstash/184047/4 "2019-07-03T16:40:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
