# Converting PTR records to IP in logstash

**URL:** <https://discuss.elastic.co/t/converting-ptr-records-to-ip-in-logstash/93915>\
**Category:** Logstash\
**Created:** [July 20, 2017, 10:47am UTC](https://discuss.elastic.co/t/converting-ptr-records-to-ip-in-logstash/93915 "2017-07-20T10:47:12Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sarfaraz\_Ahmad](https://avatars.discourse-cdn.com/v4/letter/s/67e7ee/32.png) [@Sarfaraz\_Ahmad](https://discuss.elastic.co/u/Sarfaraz_Ahmad)\
**Post date:** [July 20, 2017, 10:47am UTC](https://discuss.elastic.co/t/converting-ptr-records-to-ip-in-logstash/93915/1 "2017-07-20T10:47:12Z")

</div>

Hi ,

I am working with DNS query logs and I want the PTR record to change to the IP address.  
From : 4.3.2.1.in-addr.arpa to 1.2.3.4

I am trying to use ruby filter and add this information as a new field to the event object.  
This is what my config looks like. The code section of ruby filter.

```
           if !event.get('queryType').include? 'PTR'
                event['ip'] = event.get('queryName').match(/((?:[0-9]{0,3}.){4}?).*in/)[1].chomp(".").split(".").reverse.join(".")
           end

```

But logstash fails to startup . How do i debug this ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2017, 10:47am UTC](https://discuss.elastic.co/t/converting-ptr-records-to-ip-in-logstash/93915/2 "2017-08-17T10:47:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
