# Parse log referring the information from other services (redis, etc)

**URL:** <https://discuss.elastic.co/t/parse-log-referring-the-information-from-other-services-redis-etc/38363>\
**Category:** Logstash\
**Created:** [January 5, 2016, 3:52am UTC](https://discuss.elastic.co/t/parse-log-referring-the-information-from-other-services-redis-etc/38363 "2016-01-05T03:52:29Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Joo\_Won\_Jung](https://avatars.discourse-cdn.com/v4/letter/j/7feea3/32.png) [@Joo\_Won\_Jung](https://discuss.elastic.co/u/Joo_Won_Jung)\
**Post date:** [January 5, 2016, 3:52am UTC](https://discuss.elastic.co/t/parse-log-referring-the-information-from-other-services-redis-etc/38363/1 "2016-01-05T03:52:29Z")

</div>

Is there any way to mutate the log stream or to add more fields using other information from other services?

Case 1: add field from redis.  
Mr. A wants to add "user\_name" information using the "login\_id" in the log.  
There is a redis key-value store that maps login\_id to user\_name.

Case 2: decrypt the encrypted field.  
Mr. B wants to store the encrypted fields in the log as decrypted, plain text format.  
There is secured ReSTful service that decrypts the encrypted message.

Both cases need to request another ReSTful service.  
How can I do that in logstash script or plugin.  
Is there any best-practice to resolve the cases?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 5, 2016, 6:46am UTC](https://discuss.elastic.co/t/parse-log-referring-the-information-from-other-services-redis-etc/38363/2 "2016-01-05T06:46:07Z")

</div>

Apart from the translate service which mutates field values based on a YAML file I believe you need to write a plugin. I haven't heard of a generic one for REST or Redis lookups.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:16am UTC](https://discuss.elastic.co/t/parse-log-referring-the-information-from-other-services-redis-etc/38363/3 "2017-07-06T05:16:51Z")

</div>


