# Using for loop

**URL:** <https://discuss.elastic.co/t/using-for-loop/209810>\
**Category:** Logstash\
**Created:** [November 28, 2019, 8:35am UTC](https://discuss.elastic.co/t/using-for-loop/209810 "2019-11-28T08:35:29Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![Vikash\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_singh1/32/42119_2.png) [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Post date:** [November 28, 2019, 8:35am UTC](https://discuss.elastic.co/t/using-for-loop/209810/1 "2019-11-28T08:35:29Z")

</div>

Hey I've a file which includes ip addresses and there corresponding mac addresses. Now, is there any way I can use that file inside filter tag to match the ip address with my log file and allot them corresponding mac address??  
Example:  
filter  
{  
if [netflow][ipv4\_src\_addr] == "address\_of file(containing ip address)"  
{  
mutate { add\_field =\> {"macid" =\> "address-of file(containing mac address)"} }  
}  
Hope I am making sense

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 28, 2019, 1:53pm UTC](https://discuss.elastic.co/t/using-for-loop/209810/2 "2019-11-28T13:53:01Z")

</div>

Look at the [translate](https://www.elastic.co/guide/en/logstash/current/plugins-filters-translate.html) filter.

---

<div class="post-metadata">

**Author:** ![Vikash\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_singh1/32/42119_2.png) [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Post date:** [November 29, 2019, 3:57am UTC](https://discuss.elastic.co/t/using-for-loop/209810/3 "2019-11-29T03:57:58Z")

</div>

Thanks for pointing me at right direction..but I will have to give it manually..Is there anyway so that I can pick up the details from a file one by one and add the fields??

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 29, 2019, 6:04am UTC](https://discuss.elastic.co/t/using-for-loop/209810/4 "2019-11-29T06:04:22Z")

</div>

The translate filter is the one to use here. Why can’t you use it?

---

<div class="post-metadata">

**Author:** ![Vikash\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_singh1/32/42119_2.png) [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Post date:** [November 29, 2019, 6:13am UTC](https://discuss.elastic.co/t/using-for-loop/209810/5 "2019-11-29T06:13:54Z")

</div>

Because I will have add all the entries manually

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 29, 2019, 6:21am UTC](https://discuss.elastic.co/t/using-for-loop/209810/6 "2019-11-29T06:21:55Z")

</div>

You can add entries to the translate file and it will periodically reload the file. I do not see any other filter that would be suitable. I do suspect I still do not understand your problem and exactly what you are trying to do and why the translate filter does not fit though. Could you elaborate further?

---

<div class="post-metadata">

**Author:** ![Vikash\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_singh1/32/42119_2.png) [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Post date:** [November 29, 2019, 6:40am UTC](https://discuss.elastic.co/t/using-for-loop/209810/7 "2019-11-29T06:40:37Z")

</div>

Actually I've a file which contains the list of ip address and their respective mac address. Now, I have netflow logs v5 which doesn't contain mac address, hence I would like to add those mac address in netflow logs. I thought If I could use for loop so that it will compare from the file and if that address is found then it will add the respective mad address of that ip

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [November 29, 2019, 6:48am UTC](https://discuss.elastic.co/t/using-for-loop/209810/8 "2019-11-29T06:48:45Z")

</div>

That is exactly what the translate filter is designed for so I do not understand why you do not think this is suitable.

---

<div class="post-metadata">

**Author:** ![Vikash\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_singh1/32/42119_2.png) [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Post date:** [November 29, 2019, 7:23am UTC](https://discuss.elastic.co/t/using-for-loop/209810/9 "2019-11-29T07:23:30Z")

</div>

Oh I am so sorry I didn't go through the whole documentation

---

<div class="post-metadata">

**Author:** ![Vikash\_Singh1](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/vikash_singh1/32/42119_2.png) [@Vikash\_Singh1](https://discuss.elastic.co/u/Vikash_Singh1)\
**Post date:** [November 29, 2019, 7:24am UTC](https://discuss.elastic.co/t/using-for-loop/209810/10 "2019-11-29T07:24:01Z")

</div>

Thanks @Badger & @Christian_Dahlqvist

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 27, 2019, 7:24am UTC](https://discuss.elastic.co/t/using-for-loop/209810/11 "2019-12-27T07:24:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
