# Temporary Array for converting values

**URL:** <https://discuss.elastic.co/t/temporary-array-for-converting-values/217438>\
**Category:** Logstash\
**Created:** [January 31, 2020, 5:29pm UTC](https://discuss.elastic.co/t/temporary-array-for-converting-values/217438 "2020-01-31T17:29:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mvdlippe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mvdlippe/32/46127_2.png) [@mvdlippe](https://discuss.elastic.co/u/mvdlippe)\
**Post date:** [January 31, 2020, 5:29pm UTC](https://discuss.elastic.co/t/temporary-array-for-converting-values/217438/1 "2020-01-31T17:29:41Z")

</div>

Hello,

I am fairly new to Elastic and I have been working through getting Office 365 data into ECS format. I am looking for a solution to convert a numerical value (key) to a known string value.

I know a simple solution would be to create an if/else block and "if int = x, then string = y" but I have 40+ values for this and I do not want to turn my pipeline into a mess just to solve this problem.

The two solutions I have thought of but do not know how to properly implement would be to either make a JSON object that correlates key to value pairs that is relative to the Logstash pipeline or to store my string values in a list and have the numeric value be the index of the proper string. Either of these solutions would be exceptionally easy to program in most cases but I cannot find information on how to properly do something like this in Logstash.

From what I can tell it looks like my best option is going to be using the Ruby filter to initialize the list and use the values as the index, but I would prefer not to have to use the Ruby filter if possible.  
I have also considered the CSV filter but I have tried to work with that in the past with little success so I am not all that interested in going down that route unless the overhead of doing so is significantly less than other options.

Just looking for a little insight on how this might be handled. If there is no simple or clean solution, I might consider using scripted fields as well.

Thank you for your time!

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 31, 2020, 7:07pm UTC](https://discuss.elastic.co/t/temporary-array-for-converting-values/217438/2 "2020-01-31T19:07:42Z")

</div>

Have you looked at the [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) filter?

---

<div class="post-metadata">

**Author:** ![mvdlippe](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mvdlippe/32/46127_2.png) [@mvdlippe](https://discuss.elastic.co/u/mvdlippe)\
**Post date:** [February 3, 2020, 3:29pm UTC](https://discuss.elastic.co/t/temporary-array-for-converting-values/217438/3 "2020-02-03T15:29:28Z")

</div>

Apparently I had not, that does look like a good solution for what I am trying to do.  
Thanks for the feedback!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 2, 2020, 3:29pm UTC](https://discuss.elastic.co/t/temporary-array-for-converting-values/217438/4 "2020-03-02T15:29:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
