# Custom analyzers in Packetbeat index template

**URL:** <https://discuss.elastic.co/t/custom-analyzers-in-packetbeat-index-template/283074>\
**Category:** Beats\
**Tags:** beats-module, packetbeat\
**Created:** [September 1, 2021, 4:05pm UTC](https://discuss.elastic.co/t/custom-analyzers-in-packetbeat-index-template/283074 "2021-09-01T16:05:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![yotamgod](https://avatars.discourse-cdn.com/v4/letter/y/73ab20/32.png) [@yotamgod](https://discuss.elastic.co/u/yotamgod)\
**Post date:** [September 1, 2021, 4:05pm UTC](https://discuss.elastic.co/t/custom-analyzers-in-packetbeat-index-template/283074/1 "2021-09-01T16:05:40Z")

</div>

Hi,  
I recently started using Packetbeat and started adding my own fields to the index template (using the setup.template.append\_fields).  
I was wondering if there is some way to create a custom analyzer for my custom text fields in Packetbeat?  
My specific use-case is creating a custom "domain name" analyzer for the dns.question.name field (which I recreated as a text field under a different name). The analyzer I thought of using is something like this: [Hostname analyzer · Issue #44833 · elastic/elasticsearch · GitHub](https://github.com/elastic/elasticsearch/issues/44833)

I tried adding it like so, but the analyzer wasn't recognized:

```auto
setup.template.settings:
  analysis:
    tokenizer:
...

```

Any ideas?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 29, 2021, 6:06pm UTC](https://discuss.elastic.co/t/custom-analyzers-in-packetbeat-index-template/283074/2 "2021-09-29T18:06:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
