# Translate filter is not working

**URL:** <https://discuss.elastic.co/t/translate-filter-is-not-working/130526>\
**Category:** Logstash\
**Created:** [May 3, 2018, 8:39pm UTC](https://discuss.elastic.co/t/translate-filter-is-not-working/130526 "2018-05-03T20:39:52Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [May 3, 2018, 8:39pm UTC](https://discuss.elastic.co/t/translate-filter-is-not-working/130526/1 "2018-05-03T20:39:52Z")

</div>

Logstash Version - 6.6.2  
Translate Filter Version - 3.0.4  
Drop Filter Version - 3.0.5

logstash-config  
`=============`

input {  
stdin { codec =\> json }  
}  
filter {  
translate {  
field =\> "comp"  
dictionary\_path =\> "/etc/logstash/conf.d/comp\_enable.yml"  
}  
`# if [component] == "rabbitmq" {`  
`# if "[component]" == "%{comp}" {`  
if [component] == "%{comp}" {  
drop { }  
}  
}  
output {  
stdout { codec =\> rubydebug }  
}  
`======`

When hard-coding the value of **comp** (commented line) it works as expected - the logs are dropped, I don't get anything on console as output.

But when passing with the variable it's not working as expected.

The file /etc/logstash/conf.d/comp\_enable.yml has below contents:

"kafka": "disable"  
"rabbit": "disable"

And I am passing the below string as input logline:

{ "component":"rabbitmq" }

Anything wrong here? Can anyone from the experts group please suggest how can I achieve this?

-Bijay

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 4, 2018, 7:37pm UTC](https://discuss.elastic.co/t/translate-filter-is-not-working/130526/2 "2018-05-04T19:37:54Z")

</div>

The field you want to look up is named `component` so that's what you should put in your translate filter's `comp` option. The translate filter will then look up the contents of the `component` field in the table, and in your example it'll get a match and store "disable" in the `translation` field (if you want to store it another field you'll have to adjust the `destination` option). So, what you're looking for is probably this:

```nohighlight
if [translation] == "disable" {
  drop { }
}

```

---

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [May 5, 2018, 7:44am UTC](https://discuss.elastic.co/t/translate-filter-is-not-working/130526/3 "2018-05-05T07:44:22Z")

</div>

Thanks a lot Magnus, it worked. I have one more issue related to input config file. If the input config file is a symlink logstash is unable to read it. Is it expected behaviour?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [May 7, 2018, 5:32pm UTC](https://discuss.elastic.co/t/translate-filter-is-not-working/130526/4 "2018-05-07T17:32:02Z")

</div>

I would expect it to work, but googling the topic indicates that it doesn't actually work.

---

<div class="post-metadata">

**Author:** ![bijay](https://avatars.discourse-cdn.com/v4/letter/b/8491ac/32.png) [@bijay](https://discuss.elastic.co/u/bijay)\
**Post date:** [May 7, 2018, 5:38pm UTC](https://discuss.elastic.co/t/translate-filter-is-not-working/130526/5 "2018-05-07T17:38:38Z")

</div>

Thanks for the update Magnus..

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2018, 5:38pm UTC](https://discuss.elastic.co/t/translate-filter-is-not-working/130526/6 "2018-06-04T17:38:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
