# Replace a value to another value logstash

**URL:** <https://discuss.elastic.co/t/replace-a-value-to-another-value-logstash/310129>\
**Category:** Logstash\
**Created:** [July 20, 2022, 10:14am UTC](https://discuss.elastic.co/t/replace-a-value-to-another-value-logstash/310129 "2022-07-20T10:14:44Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mikhatanu](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mikhatanu](https://discuss.elastic.co/u/mikhatanu)\
**Post date:** [July 20, 2022, 10:14am UTC](https://discuss.elastic.co/t/replace-a-value-to-another-value-logstash/310129/1 "2022-07-20T10:14:44Z")

</div>

Hello, i have a log with an id. In another file, i have list file of the id mapping. for example id 1 has a name, description, etc in the list file. I want to replace the id in that log to the data in the list file.

Log example:

```auto
id, ip_source, ip_dest
23, x.x.x.x, y.y.y.y

```

file list example:

```auto
id, name, description
23, web_app, "this is a web app"

```

Output to elasticsearch:

```auto
23, x.x.x.x, y.y.y.y, web_app, "this is a web app"

```

can i do this all in logstash? or should i make them into their own indices in elasticsearch and filter it in kibana?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 20, 2022, 12:47pm UTC](https://discuss.elastic.co/t/replace-a-value-to-another-value-logstash/310129/2 "2022-07-20T12:47:42Z")

</div>

You can do it in logstash using the [translate filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html), the main issue is that the translate filter supports only key-value pairs, so for each key it haves just one value.

Since you have two values, `name` and `description`, you can use two files as the dictionary for the translate filters, but you can also use just one file and parse the value later.

For the second case, and considering that you are already parsing your message, your dictionary file would be something like this:

`dictionary.yml`

```auto
"23": "webapp;this is an webapp"

```

Then you will need the following filters:

```auto
translate {
	source => "id"
	target => "[@metadata][translated]"
	dictionary_path => "/path/to/the/file/dictionary.yml"
	refresh_interval => 300
}

```

When the field `id` exists as a key in the file `dictionary.yml`, this filter will create the field `[@metadata][translated]` with the value from the file, which will be `web_app;this is an web app`  
, now you can parse this field using `dissect` to extract those values in different fields.

```auto
dissect {
    mapping => {
        "[@metadata][translated]" => "%{name};%{description}"
    }
}

```

You do not need to worry about the `[@metadata][translated]` in your documents, this is a temporary field that will not be present in your output.

If you want a longer explanation about the `translate` filter, I've made a [blog post](https://web.leandrojmp.com/posts/en/2021/02/logstash-translate) about it a couple of time ago.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2022, 12:47pm UTC](https://discuss.elastic.co/t/replace-a-value-to-another-value-logstash/310129/3 "2022-08-17T12:47:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
