# Relating two fields - using translate or mutate

**URL:** <https://discuss.elastic.co/t/relating-two-fields-using-translate-or-mutate/115734>\
**Category:** Logstash\
**Created:** [January 16, 2018, 2:36pm UTC](https://discuss.elastic.co/t/relating-two-fields-using-translate-or-mutate/115734 "2018-01-16T14:36:13Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [January 16, 2018, 2:36pm UTC](https://discuss.elastic.co/t/relating-two-fields-using-translate-or-mutate/115734/1 "2018-01-16T14:36:13Z")

</div>

Hi All,

I have a index for netflow data and recently I was trying to use the combine threat intelligence to see if there is any communication from any black listed ip's.

I have two tags one is **netflow** and other one is **threat** but same index.

Is it possible to relate the netflow data and entity threat field. Something like this in the logstash filter,

```auto
filter {
  if [netflow][ipv4_src_addr] == [entity_threat] {
    mutate {
      add_tag => "true"
    }
  } else {
  if [netflow][ipv4_dst_addr] == [entity_threat] {
    mutate {
      add_tag => "true"
    }
  }
}

```

Am not sure if am doing it correctly, please anyone help me in figuring it out.

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 17, 2018, 3:37pm UTC](https://discuss.elastic.co/t/relating-two-fields-using-translate-or-mutate/115734/2 "2018-01-17T15:37:12Z")

</div>

I don't know how you are planning to use the translate filter here, but I can comment on your snippet above.

> [@Raj\_Kumar](#):
>
> I have two tags one is netflow and other one is threat but same index.

By tags above do you mean `fields` and by index above do you mean `value`?

Does it make sense to use a tag of "true" because you can't tell which branch caused that tag to be added? Surely the tags `"source-address-is-entity-threat"` and `"destination-address-is-entity-threat"` would be better.

Maybe add a field called `[netflow][threat_detected]` with a value of "source", "destination" or else "inconclusive" depending on the branch the conditional takes.

Also your else if nesting is not quite correct...

```auto
filter {
  if [netflow][ipv4_src_addr] == [entity_threat] {
    mutate {
      add_tag => "true"
    }
  } else if [netflow][ipv4_dst_addr] == [entity_threat] {
    mutate {
      add_tag => "true"
    }
  }
}

```

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [January 18, 2018, 1:36pm UTC](https://discuss.elastic.co/t/relating-two-fields-using-translate-or-mutate/115734/3 "2018-01-18T13:36:22Z")

</div>

Hi Guyboertje,

Thanks for the reply. Sorry for the confusion ,let me explain in another way , i have one index called **logstash\_netflow-** \* for netflow data and have another index called **logstash\_threat-** \* for threat intelligence feed and it has list of black listed ip's.

So am not sure whether we can relate the field (src\_addr or dst\_addr) from **logstash\_netflow-** \* to another field (entity\_threat) from another index ie **logstash\_threat-** \*

So what I did is I used the threat intelligence feed to the logstash\_netflow index. So now I have only one index which is **logstash\_netflow-** \*

Now, I want to match the field src\_addr and dst\_addr to the another field which is entitiy\_threat ,example like this .

if [netflow][ipv4\_dst\_addr] == [entity\_threat] ----------\> Add field like source threat true or something  
if if [netflow][ipv4\_dst\_addr] == [entity\_threat] -----------\> Add field like destination threat true or something

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [January 18, 2018, 3:00pm UTC](https://discuss.elastic.co/t/relating-two-fields-using-translate-or-mutate/115734/4 "2018-01-18T15:00:50Z")

</div>

Ahhh. I see.

You can keep the two indexes separate.

Use the elasticsearch filter in your netflow stream to do a query on the logstash\_threat-\* index using the value from `[netflow][ipv4_src_addr]` in the query to find a matching document and `add_tag` will be invoked if there is a match. This means that you must have two elasticsearch filters one for each field.  
If you only care that a threat is found on either src or dst then you might be able to use one elasticsearch filter with some sort of OR in the query.  
Links:

1. [Stackoverflow](https://stackoverflow.com/questions/37970929/elasticsearch-filter-plugin-from-logstash-rejects-negative-numbers)
2. [Docs for ES filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-elasticsearch.html)
3. [ES Query Docs](https://www.elastic.co/guide/en/elasticsearch/reference/master/query-dsl-query-string-query.html#query-string-syntax)

Using `translate` will need the same two filter solution but you will have to export the threat IP addresses to a CVS file.

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [February 7, 2018, 9:02am UTC](https://discuss.elastic.co/t/relating-two-fields-using-translate-or-mutate/115734/5 "2018-02-07T09:02:53Z")

</div>

Hi Guy,

Thanks for the reply, is it possible for you to create a sample translate and elasticsearch filter, to execute this function

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2018, 9:02am UTC](https://discuss.elastic.co/t/relating-two-fields-using-translate-or-mutate/115734/6 "2018-03-07T09:02:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
