# Translate plugin doesn't work

**URL:** <https://discuss.elastic.co/t/translate-plugin-doesnt-work/54034>\
**Category:** Logstash\
**Created:** [June 27, 2016, 12:01pm UTC](https://discuss.elastic.co/t/translate-plugin-doesnt-work/54034 "2016-06-27T12:01:39Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Alexey\_Khudyakov](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@Alexey\_Khudyakov](https://discuss.elastic.co/u/Alexey_Khudyakov)\
**Post date:** [June 27, 2016, 12:01pm UTC](https://discuss.elastic.co/t/translate-plugin-doesnt-work/54034/1 "2016-06-27T12:01:39Z")

</div>

Dear community,

I tried to add descriptions of network protocols but unfortunately it doesn't work ☹

Here is the part of logstash's config file

```
   #Protocol friendly naming
   translate {
      field => "[netflow][protocol]"
      dictionary => [6, "TCP", 17, "UDP", 1, "ICMP", 47, "GRE", 50, "ESP"]
   }

```

But the new field with translation didn't appear and I don't understand why.

---

<div class="post-metadata">

**Author:** ![purbon](https://avatars.discourse-cdn.com/v4/letter/p/edb3f5/32.png) [@purbon](https://discuss.elastic.co/u/purbon)\
**Post date:** [June 27, 2016, 3:58pm UTC](https://discuss.elastic.co/t/translate-plugin-doesnt-work/54034/2 "2016-06-27T15:58:55Z")

</div>

With the current version the translate plugin only accept single field references, not field references. I think this that this is what is wrong for your config. I agree it would be very nice to have , could you open an issue at [https://github.com/logstash-plugins/logstash-filter-translate](https://github.com/logstash-plugins/logstash-filter-translate)

- purbon

---

<div class="post-metadata">

**Author:** ![Alexey\_Khudyakov](https://avatars.discourse-cdn.com/v4/letter/a/dfb087/32.png) [@Alexey\_Khudyakov](https://discuss.elastic.co/u/Alexey_Khudyakov)\
**Post date:** [June 28, 2016, 7:23am UTC](https://discuss.elastic.co/t/translate-plugin-doesnt-work/54034/3 "2016-06-28T07:23:18Z")

</div>

Hi Purbon,  
Thank you for your answer.  
I solved the issue. I re-read the documentation and paid attention on this "Make sure you specify any integer-based keys in quotes"  
And after taking integer keys in quotes all works perfectly 🙂

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [June 28, 2016, 11:53pm UTC](https://discuss.elastic.co/t/translate-plugin-doesnt-work/54034/4 "2016-06-28T23:53:46Z")

</div>

> [@Alexey\_Khudyakov](#):
>
> I solved the issue. I re-read the documentation and paid attention on this "Make sure you specify any integer-based keys in quotes"And after taking integer keys in quotes all works perfectly

Can you post the config you have, it may be useful for others in future as well 🙂

---

<div class="post-metadata">

**Author:** ![jaychris](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@jaychris](https://discuss.elastic.co/u/jaychris)\
**Post date:** [August 5, 2016, 6:59pm UTC](https://discuss.elastic.co/t/translate-plugin-doesnt-work/54034/5 "2016-08-05T18:59:55Z")

</div>

I'd love to see your working config, I've run in to the same problem. I'm using this filter:

```
filter {
  translate {
    field => "[netflow][protocol]"
    dictionary => [
		   "2", "IGMP",
		   "17", "UDP",
	    	   "50", "ESP",
		   "89", "OSPF"
		 ]
  }
}

```

but no luck. Data in ES still shows the integer value for netflow.protocol, instead of the translated value.

---

<div class="post-metadata">

**Author:** ![jaychris](https://avatars.discourse-cdn.com/v4/letter/j/d78d45/32.png) [@jaychris](https://discuss.elastic.co/u/jaychris)\
**Post date:** [August 5, 2016, 7:06pm UTC](https://discuss.elastic.co/t/translate-plugin-doesnt-work/54034/6 "2016-08-05T19:06:17Z")

</div>

Oops, never mind. I too read the documentation more closely. By default, the translated value shows up in a new field called "translation". You need to specify a destination field (destination =\> "[netflow][some\_field]") to use a different field. If you specify the same field as the source field, it will replace the value. I also added "override =\> true", though I am not certain it's required for this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:44am UTC](https://discuss.elastic.co/t/translate-plugin-doesnt-work/54034/7 "2017-07-06T04:44:28Z")

</div>


