# Translate two fields in one event

**URL:** <https://discuss.elastic.co/t/translate-two-fields-in-one-event/130516>\
**Category:** Logstash\
**Created:** [May 3, 2018, 7:13pm UTC](https://discuss.elastic.co/t/translate-two-fields-in-one-event/130516 "2018-05-03T19:13:47Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![john.bennett](https://avatars.discourse-cdn.com/v4/letter/j/ec9cab/32.png) [@john.bennett](https://discuss.elastic.co/u/john.bennett)\
**Post date:** [May 3, 2018, 7:13pm UTC](https://discuss.elastic.co/t/translate-two-fields-in-one-event/130516/1 "2018-05-03T19:13:47Z")

</div>

HI,  
I have two translate blocks I am trying to translate two different fields from two dictionary yaml files. One for user name, one for IP.  
So far, the first translate block is the only one that works. If IP is first then it works , if the USERNAME block is first it works fine. Just not both translates for IP and USERNAME at the name time. Odd? Help. The ssh grok I got from elasticsearch.

? How to get both translates to work on an event ( one event ) ? 🤔

My test code; for logstash, in the filter block.

if [source] == "/var/log/secure" {  
grok {  
id =\> "ssh"  
match =\> { "message" =\> "Accepted %{WORD:auth\_method} for %{USER:username} from %{IP:src\_ip} port %{INT:src\_port} ssh2" }  
add\_field =\> ["ip\_string", "%{src\_ip}"]  
}

mutate {  
add\_tag =\> ["source\_secure\_ssh"]  
convert =\> { "ip\_string" =\> "string" }  
}

translate {  
id =\> "scr\_ip"  
dictionary\_path =\> '/home/debug/ip.yaml'  
field =\> "ip\_string"  
add\_tag =\> ["match\_ip"]  
add\_field =\> { "iplookup" =\> "match %{ip\_string}" }  
}

translate {  
id =\> "username"  
dictionary\_path =\> '/home/debug/username.yaml'  
field =\> "username"  
add\_tag =\> ["match\_username"]  
add\_field =\> { "userlookup" =\> "match %{username}" }  
}

}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 3, 2018, 7:51pm UTC](https://discuss.elastic.co/t/translate-two-fields-in-one-event/130516/2 "2018-05-03T19:51:44Z")

</div>

Both filters have a destination field called "translation" (the default) and override set to false (the default) so the second one does not do a translation.

---

<div class="post-metadata">

**Author:** ![john.bennett](https://avatars.discourse-cdn.com/v4/letter/j/ec9cab/32.png) [@john.bennett](https://discuss.elastic.co/u/john.bennett)\
**Post date:** [May 3, 2018, 10:53pm UTC](https://discuss.elastic.co/t/translate-two-fields-in-one-event/130516/3 "2018-05-03T22:53:10Z")

</div>

Badger, thanks for the tip.

I added;  
override =\> true  
to each translate block, now each translate block does the translate a-ok.  
I did not use the destination directive , as I am all ready adding a field in each block.

JB 🕶

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 31, 2018, 10:53pm UTC](https://discuss.elastic.co/t/translate-two-fields-in-one-event/130516/4 "2018-05-31T22:53:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
