# Translate filter plugin

**URL:** <https://discuss.elastic.co/t/translate-filter-plugin/167971>\
**Category:** Logstash\
**Created:** [February 12, 2019, 7:34am UTC](https://discuss.elastic.co/t/translate-filter-plugin/167971 "2019-02-12T07:34:00Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Michael.Swiss](https://avatars.discourse-cdn.com/v4/letter/m/c5a1d2/32.png) [@Michael.Swiss](https://discuss.elastic.co/u/Michael.Swiss)\
**Post date:** [February 12, 2019, 7:34am UTC](https://discuss.elastic.co/t/translate-filter-plugin/167971/1 "2019-02-12T07:34:01Z")

</div>

Dear colleagues

I am using many translate filter plugins to mutate data in logstash. The filter requires me to create a dictionary file (.yaml) that contains 2 columns. That way I need lots of .yaml files.  
For me it would be much easier if there were either:

- A filter plugin that creates These yaml dictionary files out of e.g. one .csv file
- A dictionary file format that contains several columns. Here I would need to specify the column out of which the target value would be pulled. Similar to Excel "vlookup(...)"

Does either way work today or in the future?

Best Michael

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 12, 2019, 8:01am UTC](https://discuss.elastic.co/t/translate-filter-plugin/167971/2 "2019-02-12T08:01:43Z")

</div>

If you want to enrich with more complex data you can always format the string as JSON and then use a JSON filter to parse it:

```auto
input {
  generator {
    lines => ['test']
    count => 1
  } 
} 

filter{
  translate {
    field => "message"
    dictionary => {
      "test" => '{"a":1,"b":2}'
    }
  }

  json {
    source => "translation"
    remove_field => ["translation"]
  }
}

output { stdout { codec => rubydebug} }

```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 12, 2019, 2:21pm UTC](https://discuss.elastic.co/t/translate-filter-plugin/167971/3 "2019-02-12T14:21:48Z")

</div>

That works OK with JSON, but it does not work very well with a simple multi-column CSV file. You only get the second column back as the translation.

I think it might be useful to have a lookup filter that would return a row of the CSV as a hash, but I'm struggling to come up with the right interface for it.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [February 12, 2019, 2:45pm UTC](https://discuss.elastic.co/t/translate-filter-plugin/167971/4 "2019-02-12T14:45:14Z")

</div>

Yes, you are indeed right.

---

<div class="post-metadata">

**Author:** ![guyboertje](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/guyboertje/32/31592_2.png) [@guyboertje](https://discuss.elastic.co/u/guyboertje)\
**Post date:** [February 12, 2019, 3:34pm UTC](https://discuss.elastic.co/t/translate-filter-plugin/167971/5 "2019-02-12T15:34:08Z")

</div>

@Michael.Swiss

How would you specify the "VLOOKUP" column? I mean where would it come from? A field?

If so, then a Key, JSON string value can work.  
You put the JSON object into the event with the translate and the JSON filter, as per Christians example but moving the remove field, and then use:

```auto
  mutate {
    rename => {"final_field" => "[translation][%{second_key}]"}
    remove_field => ["translation"]
  }

```

---

<div class="post-metadata">

**Author:** ![yaauie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yaauie/32/23363_2.png) [@yaauie](https://discuss.elastic.co/u/yaauie)\
**Post date:** [February 26, 2019, 4:55pm UTC](https://discuss.elastic.co/t/translate-filter-plugin/167971/6 "2019-02-26T16:55:54Z")

</div>

The Translate Filter accepts a CSV:

> The currently supported formats are YAML, JSON, and CSV. Format selection is based on the file extension: `json` for JSON, `yaml` or `yml` for YAML, and `csv` for CSV. The CSV format expects exactly two columns, with the first serving as the original text (lookup key), and the second column as the translation.
> 
> -- [Logstash Translate Filter: `dictionary_path`](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-dictionary_path)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 26, 2019, 4:56pm UTC](https://discuss.elastic.co/t/translate-filter-plugin/167971/7 "2019-03-26T16:56:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
