# Translate multiple fields in an event

**URL:** <https://discuss.elastic.co/t/translate-multiple-fields-in-an-event/78502>\
**Category:** Logstash\
**Created:** [March 14, 2017, 11:33am UTC](https://discuss.elastic.co/t/translate-multiple-fields-in-an-event/78502 "2017-03-14T11:33:46Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![tsangdl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsangdl/32/12835_2.png) [@tsangdl](https://discuss.elastic.co/u/tsangdl)\
**Post date:** [March 14, 2017, 11:33am UTC](https://discuss.elastic.co/t/translate-multiple-fields-in-an-event/78502/1 "2017-03-14T11:33:46Z")

</div>

Hi,

I have events going into logstash. Each event has a number of fields two of which I would like to translate  
The fields are customer\_id and integrator\_id.  
I would like to add fields customer\_name and integrator\_name, the "id-to-name" translations coming from csv files.  
I can translate one field but how would two be translated.

logstash.conf has: (obviously this doesn't work)  
...  
translate {  
dictionary\_path =\> "/etc/logstash/clients.csv"  
field =\> "[client\_id]"  
add\_field =\> { "client\_name" =\> "%{[translation]}" }  
}  
translate {  
dictionary\_path =\> "/etc/logstash/integrators.csv"  
field =\> "[integrator\_id]"  
add\_field =\> { "integrator\_name" =\> "%{[translation]}" }  
}

...

Thanks in advance

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 14, 2017, 1:11pm UTC](https://discuss.elastic.co/t/translate-multiple-fields-in-an-event/78502/2 "2017-03-14T13:11:51Z")

</div>

There is no need to add a field if you instead specify the [destination](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-destination) of the translation in the translate filter.

---

<div class="post-metadata">

**Author:** ![tsangdl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tsangdl/32/12835_2.png) [@tsangdl](https://discuss.elastic.co/u/tsangdl)\
**Post date:** [March 16, 2017, 3:45am UTC](https://discuss.elastic.co/t/translate-multiple-fields-in-an-event/78502/3 "2017-03-16T03:45:49Z")

</div>

Christian,

Thankyou for your reply.  
In my case, client\_id is numeric and client\_name text. Also client\_name does not exist and I need it for later.

I also have the integrator\_id field which I would like to translate at the same time as the client\_id but am not sure how to specify two different fields for translation in the same block of code.

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [March 16, 2017, 4:23am UTC](https://discuss.elastic.co/t/translate-multiple-fields-in-an-event/78502/4 "2017-03-16T04:23:32Z")

</div>

> [@tsangdl](#):
>
> I also have the integrator\_id field which I would like to translate at the same time as the client\_id but am not sure how to specify two different fields for translation in the same block of code.

Per [Translate filter plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-field), value type is `string` so it takes only one field per translate block. Also, it is stated clearly in the docs that

> If this field is an array, only the first value will be used.

This filter block should work for you

```auto
translate {
    dictionary_path => "/etc/logstash/clients.csv"
    field => "client_id"
    destination => "client_name"
}

translate {
    dictionary_path => "/etc/logstash/integrators.csv"
    field => "integrator_id"
    destination => "integrator_name"    
}

```

> [@tsangdl](#):
>
> I can translate one field but how would two be translated.

Do you mean LS fails to translate one of the fields in two separate translate blocks? If it fails when you try to put two fields into the `field =>` setting, the reason is above.

In addition, numeric keys must be double quoted [Translate filter plugin | Logstash Reference [8.11] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html#plugins-filters-translate-dictionary_path)

---

<div class="post-metadata">

**Author:** ![bryan\_stuhlsatz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryan_stuhlsatz/32/49123_2.png) [@bryan\_stuhlsatz](https://discuss.elastic.co/u/bryan_stuhlsatz)\
**Post date:** [March 16, 2017, 4:35am UTC](https://discuss.elastic.co/t/translate-multiple-fields-in-an-event/78502/5 "2017-03-16T04:35:29Z")

</div>

I agree with tsangdl. Sounds like all your data is in a single event so the below should work. If the events were not of same format, or you are processing different pieces, you could use IF statements. This should work:  
filter {  
translate {  
dictionary\_path =\> "/etc/logstash/clients.csv"  
field =\> "client\_id"  
destination =\> "client\_name"  
}  
translate {  
dictionary\_path =\> "/etc/logstash/integrators.csv"  
field =\> "integrator\_id"  
destination =\> "integrator\_name"  
}  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 13, 2017, 4:35am UTC](https://discuss.elastic.co/t/translate-multiple-fields-in-an-event/78502/6 "2017-04-13T04:35:53Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
