# Send log files by filebeat cisco module to logstash

**URL:** <https://discuss.elastic.co/t/send-log-files-by-filebeat-cisco-module-to-logstash/198281>\
**Category:** Logstash\
**Created:** [September 5, 2019, 3:20pm UTC](https://discuss.elastic.co/t/send-log-files-by-filebeat-cisco-module-to-logstash/198281 "2019-09-05T15:20:25Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bublik96](https://avatars.discourse-cdn.com/v4/letter/b/ba9def/32.png) [@bublik96](https://discuss.elastic.co/u/bublik96)\
**Post date:** [September 5, 2019, 3:20pm UTC](https://discuss.elastic.co/t/send-log-files-by-filebeat-cisco-module-to-logstash/198281/1 "2019-09-05T15:20:25Z")

</div>

Hello!,

I am using ELK to analyze log files for example from Cisco firewall by filebeat cisco module, and I want compare IP's from this logs with file which consist bad IP's.

I came to the conclusion to send log files by filebeat cisco module to logstash and use translate.

Here is my conf:

`  
filter {  
translate {  
dictionary\_path =\> "/path to/file.yaml"  
field =\> "destination.ip" # "[destination][ip]" try too  
destination =\> "DESTIOC"  
override =\> true  
}

translate {  
dictionary\_path =\> "/path to/file.yaml"  
field =\> "source.ip" # "[source][ip]" try too  
destination =\> "SRCIOC"  
override =\> true  
}

}

output {  
elasticsearch {  
hosts =\> "elastic\_ip:9200"  
manage\_template =\> false  
index =\> "[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
pipeline =\> "%{[@metadata][pipeline]}"  
user =\> "elastic"  
password =\> "secret"  
}  
stdout {  
codec =\> rubydebug  
}

}

`

I can see that the logs are coming, but the translation doesnt work.

Where my mistake ??? Help me please.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 3, 2019, 3:28pm UTC](https://discuss.elastic.co/t/send-log-files-by-filebeat-cisco-module-to-logstash/198281/2 "2019-10-03T15:28:35Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
