# Translate Filter Destination

**URL:** <https://discuss.elastic.co/t/translate-filter-destination/133406>\
**Category:** Beats\
**Created:** [May 26, 2018, 7:45pm UTC](https://discuss.elastic.co/t/translate-filter-destination/133406 "2018-05-26T19:45:10Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![empfangsfehler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/empfangsfehler/32/31520_2.png) [@empfangsfehler](https://discuss.elastic.co/u/empfangsfehler)\
**Post date:** [May 26, 2018, 7:45pm UTC](https://discuss.elastic.co/t/translate-filter-destination/133406/1 "2018-05-26T19:45:10Z")

</div>

Hi there,

i would like to store my translated field as "dhcp.EventName" but it seems not to work, the field is never created or filled. I haven't found anything in the documentation about this.

I tried the following configurations:

```
....
if "dhcpservice" in [tags] {
	grok {
		match => { "message" => ['^%{NUMBER:dhcp.EventID},%{GREEDYDATA}'] }
	}
	mutate {
		convert => ["[dhcp][EventID]", "integer"]
	}
	translate {
		field => "[dhcp][EventID]"
		destination => "[dhcp][EventName]"
		override => false
		dictionary_path => "/etc/logstash/dhcpdirectory.yml"
	}
}
....

```

or

```
....
if "dhcpservice" in [tags] {
	grok {
		match => { "message" => ['^%{NUMBER:dhcp.EventID},%{GREEDYDATA}'] }
	}
	mutate {
		convert => ["[dhcp][EventID]", "integer"]
	}
	translate {
		field => "[dhcp][EventID]"
		destination => "dhcp.EventName"
		override => false
		dictionary_path => "/etc/logstash/dhcpdirectory.yml"
	}
}
....

```

and even

```
....
if "dhcpservice" in [tags] {
	grok {
		match => { "message" => ['^%{NUMBER:dhcp.EventID},%{GREEDYDATA}'] }
	}
	mutate {
		convert => ["[dhcp][EventID]", "integer"]
		add_field => { "dhcp.EventName" => "Sampledata" }
	}
	translate {
		field => "[dhcp][EventID]"
		destination => "[dhcp][EventName]"
		override => true
		dictionary_path => "/etc/logstash/dhcpdirectory.yml"
	}
}
....
```

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [May 27, 2018, 6:30am UTC](https://discuss.elastic.co/t/translate-filter-destination/133406/2 "2018-05-27T06:30:28Z")

</div>

What does a sample event look like?

---

<div class="post-metadata">

**Author:** ![empfangsfehler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/empfangsfehler/32/31520_2.png) [@empfangsfehler](https://discuss.elastic.co/u/empfangsfehler)\
**Post date:** [May 27, 2018, 10:15am UTC](https://discuss.elastic.co/t/translate-filter-destination/133406/3 "2018-05-27T10:15:25Z")

</div>

Find all three variants in the same order as in the original post on gist:

[https://gist.github.com/empfangsfehler/11ae147d01cce05dc98c886364375c88](https://gist.github.com/empfangsfehler/11ae147d01cce05dc98c886364375c88)

[https://gist.github.com/empfangsfehler/5e1048e8104d2c8e7d35789c0669eb02](https://gist.github.com/empfangsfehler/5e1048e8104d2c8e7d35789c0669eb02)

[https://gist.github.com/empfangsfehler/bb6bb6c41ee247d6e7fd0e73bf8eda4c](https://gist.github.com/empfangsfehler/bb6bb6c41ee247d6e7fd0e73bf8eda4c)

Also the event which is read by Filebeat from a LogFile looks like that:

`32,05/27/18,12:12:59,,172.16.50.230,LTK17024,,,0,6,,AAEBI7eicVFkGI8afQ0ILX0kB+R1WATYvcpJHhf0CihMicI=,`

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [May 27, 2018, 1:04pm UTC](https://discuss.elastic.co/t/translate-filter-destination/133406/4 "2018-05-27T13:04:19Z")

</div>

What does your `dhcpdirectory.yml` look like?

---

<div class="post-metadata">

**Author:** ![empfangsfehler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/empfangsfehler/32/31520_2.png) [@empfangsfehler](https://discuss.elastic.co/u/empfangsfehler)\
**Post date:** [May 27, 2018, 1:19pm UTC](https://discuss.elastic.co/t/translate-filter-destination/133406/5 "2018-05-27T13:19:35Z")

</div>

[https://gist.github.com/empfangsfehler/8ed74df44d025bc6b132300a12cf091d](https://gist.github.com/empfangsfehler/8ed74df44d025bc6b132300a12cf091d)

The Translate itself works fine when i use "dhcpEventName" as destination but not when i would like to save in a nested field.

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [May 27, 2018, 2:13pm UTC](https://discuss.elastic.co/t/translate-filter-destination/133406/6 "2018-05-27T14:13:06Z")

</div>

A couple of things to consider...

1. You convert dhcp.EventID to an integer before the lookup. So the values 00, 01, 02 will likely not match as dhcp.EventID will contain 0, 1, 2. The values that are not 0-padded should be fine.

2. Add fallback =\> "_UNKNOWN_" to your translate filter. This will at least let you know whether the lookup is failing to find a match, or if the lookup is not even happening.

3. I would also recommend getting rid of the `override` setting unless the `field` and `destination` are the same field.

Here are a couple of examples that work fine for me...

```auto
translate {
  dictionary_path => "${ELASTIFLOW_DICT_PATH:/etc/logstash/elastiflow/dictionaries}/iana_protocol_numbers.yml"
  field => "[flow][ip_protocol]"
  destination => "[flow][ip_protocol]"
  fallback => "UNKNOWN(%{[flow][ip_protocol]})"
  override => true
}

```

```auto
translate {
  dictionary_path => "${ELASTIFLOW_DICT_PATH:/etc/logstash/elastiflow/dictionaries}/iana_service_names_udp.yml"
  field => "[flow][src_port]"
  destination => "[flow][src_port_name]"
  fallback => "__UNKNOWN"
}

```

---

<div class="post-metadata">

**Author:** ![empfangsfehler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/empfangsfehler/32/31520_2.png) [@empfangsfehler](https://discuss.elastic.co/u/empfangsfehler)\
**Post date:** [May 27, 2018, 2:41pm UTC](https://discuss.elastic.co/t/translate-filter-destination/133406/7 "2018-05-27T14:41:23Z")

</div>

Thanks!

I moved the integer `convert` after the `translate`.

The field is still not there - do you add this before the translate manually with mutate?

Here is my translate now:

```
translate {
	field => "[dhcp][EventID]"
	destination => "[dhcp][EventDescription]"
	dictionary_path => "/etc/logstash/dhcpdirectory.yml"
	fallback => "_UNKNOWN"
}

```

I tried also by setting the destination to `dhcp.EventDescription`

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [May 27, 2018, 3:02pm UTC](https://discuss.elastic.co/t/translate-filter-destination/133406/8 "2018-05-27T15:02:47Z")

</div>

The only things that I can think of...

1. I never use dot notation to refer to nested fields. Try changing `%{NUMBER:dhcp.EventID}` to `%{NUMBER:[dhcp][EventID]}`. I realize that the grok debugger allows dot notation, but the grok debugger has a few inconsistencies with Logstash itself. The reason I wonder about this is that your sample data shows an underscore for the field name: `"dhcp_EventID": 11,`

2. If the above is not the issue, I question whether the `"dhcpservice" in [tags]` is actually matching.

---

<div class="post-metadata">

**Author:** ![empfangsfehler](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/empfangsfehler/32/31520_2.png) [@empfangsfehler](https://discuss.elastic.co/u/empfangsfehler)\
**Post date:** [May 27, 2018, 3:19pm UTC](https://discuss.elastic.co/t/translate-filter-destination/133406/9 "2018-05-27T15:19:55Z")

</div>

Now it works fine - i changed the GROK pattern from dot notation to square brackets notation.

Thanks for all!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 24, 2018, 5:19pm UTC](https://discuss.elastic.co/t/translate-filter-destination/133406/10 "2018-06-24T17:19:58Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
