# Reverse\_mapping for cef input codec not working

**URL:** <https://discuss.elastic.co/t/reverse-mapping-for-cef-input-codec-not-working/169184>\
**Category:** Logstash\
**Created:** [February 20, 2019, 10:51am UTC](https://discuss.elastic.co/t/reverse-mapping-for-cef-input-codec-not-working/169184 "2019-02-20T10:51:43Z")\
**Posts on this page:** 1\
**Showing post:** 2

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 20, 2019, 12:50pm UTC](https://discuss.elastic.co/t/reverse-mapping-for-cef-input-codec-not-working/169184/2 "2019-02-20T12:50:59Z")

</div>

The reverse\_mapping option is for output. So

```
   output { stdout { codec => cef { reverse_mapping => false fields => ["sourceAddress", "deviceCustomString4Label"] } } }

```

will get you

```
CEF:0|Elasticsearch|Logstash|1.0|Logstash|Logstash|6|sourceAddress=10.1.100.17 deviceCustomString4Label=ICMP Type

```

and if you flip that to true you get

```
CEF:0|Elasticsearch|Logstash|1.0|Logstash|Logstash|6|src=10.1.100.17 cs4Label=ICMP Type
```

---

_[View the full topic](https://discuss.elastic.co/t/reverse-mapping-for-cef-input-codec-not-working/169184)._
