# DNS filter couldn't perform reverse lookup

**URL:** <https://discuss.elastic.co/t/dns-filter-couldnt-perform-reverse-lookup/230856>\
**Category:** Logstash\
**Created:** [May 3, 2020, 9:59am UTC](https://discuss.elastic.co/t/dns-filter-couldnt-perform-reverse-lookup/230856 "2020-05-03T09:59:38Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ladakalina](https://avatars.discourse-cdn.com/v4/letter/l/76d3ee/32.png) [@ladakalina](https://discuss.elastic.co/u/ladakalina)\
**Post date:** [May 3, 2020, 9:59am UTC](https://discuss.elastic.co/t/dns-filter-couldnt-perform-reverse-lookup/230856/1 "2020-05-03T09:59:38Z")

</div>

Hello everyone!  
I have a problem with DNS filter in Logstash.  
**Source data:** I use logstash to parse ulogd logs from my router (based on Open-wrt). The last problem I faced it's problem with perform reverse lookup IP-address.

**1) Elastic version:**  
curl -XGET 'localhost:9200'  
{  
"name" : "\*\*\*\*\*",  
"cluster\_name" : "elasticsearch",  
"cluster\_uuid" : "XnrCNwIbT4yLpg5wnpDHFA",  
"version" : {  
"number" : "7.6.2",  
"build\_flavor" : "default",  
"build\_type" : "deb",  
"build\_hash" : "ef48eb35cf30adf4db14086e8aabd07ef6fb113f",  
"build\_date" : "2020-03-26T06:34:37.794943Z",  
"build\_snapshot" : false,  
"lucene\_version" : "8.4.0",  
"minimum\_wire\_compatibility\_version" : "6.8.0",  
"minimum\_index\_compatibility\_version" : "6.0.0-beta1"  
},  
"tagline" : "You Know, for Search"  
}

**2) Logstash config:**

input {  
udp {  
port =\> 5014  
type =\> syslog  
}  
}  
filter {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:sys$  
}  
grok {  
match =\> { "syslog\_message" =\> "[%{DATA:status}] %{DATA:outbound.direction}: SRC=%{IP:outbound.src\_ip} DST=%{IP:outbound.dst\_ip} PROTO=%{WORD:outbound.protocol$  
}  
geoip {  
source =\> "outbound.dst\_ip"  
target =\> "outboundgeoip"  
add\_field =\> ["[outboundgeoip][coord]", "%{[outboundgeoip][longitude]}" ]  
add\_field =\> ["[outboundgeoip][coord]", "%{[outboundgeoip][latitude]}" ]  
}  
geoip {  
source =\> "inbound.src\_ip"  
target =\> "inboundgeoip"  
add\_field =\> ["[inboundgeoip][coord]", "%{[inboundgeoip][longitude]}" ]  
add\_field =\> ["[inboundgeoip][coord]", "%{[inboundgeoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[outboundgeoip][coord]", "float" ]  
convert =\> ["[inboundgeoip][coord]", "float" ]  
}  
dns {  
reverse =\> ["[outbound][dst\_ip]" ]  
nameserver =\> ["8.8.8.8"]  
action =\> "append"  
add\_tag =\> ["dns\_successful\_lookup"]  
}  
}  
output {  
elasticsearch {  
hosts =\> ["[http://localhost:9200](http://localhost:9200)"]  
index =\> "syslog-%{+YYYY.MM.dd}"  
}  
}

**3) Problem with result:**

**logstash[2856]: [2020-05-03T09:36:10,889][WARN][logstash.filters.dns][main] DNS filter could not perform reverse lookup on missing field {:field=\>"[outbound][dst\_ip]"}**

 ![log](https://us1.discourse-cdn.com/elastic/original/3X/0/5/05a3cf535b60f807f9b01d5f550e06a1da84328f.png)  
I have outbound.dst\_ip with IP-address without dns-name. It's problem with all logs.  
I ask for your help or advice to solve this problem.

---

<div class="post-metadata">

**Author:** ![ptamba](https://avatars.discourse-cdn.com/v4/letter/p/7feea3/32.png) [@ptamba](https://discuss.elastic.co/u/ptamba)\
**Post date:** [May 3, 2020, 10:59am UTC](https://discuss.elastic.co/t/dns-filter-couldnt-perform-reverse-lookup/230856/2 "2020-05-03T10:59:39Z")

</div>

as the log suggested, it couldn’t find the field [oubound][dst\_ip]. change the field in your dns filter into outbound.dst\_ip instead or assign value to the [outbound].[dst\_ip]

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 3, 2020, 2:13pm UTC](https://discuss.elastic.co/t/dns-filter-couldnt-perform-reverse-lookup/230856/3 "2020-05-03T14:13:18Z")

</div>

A field can have a period in its name, in which case logstash would call it

```
[outbound.dst_ip]

```

or a field can be an object that contains another field, in which case logstash would call it

```
[outbound][dst_ip]

```

You are mixing the two.

---

<div class="post-metadata">

**Author:** ![ladakalina](https://avatars.discourse-cdn.com/v4/letter/l/76d3ee/32.png) [@ladakalina](https://discuss.elastic.co/u/ladakalina)\
**Post date:** [May 4, 2020, 6:00pm UTC](https://discuss.elastic.co/t/dns-filter-couldnt-perform-reverse-lookup/230856/4 "2020-05-04T18:00:42Z")

</div>

Really. The problem was the wrong field name. Thanks.

Correct log:

```
dns {
  reverse => ["outbound.dst_ip"]
  nameserver => ["8.8.8.8"]
  action => "append"
  add_tag => ["dns_successful_lookup"]
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 1, 2020, 6:00pm UTC](https://discuss.elastic.co/t/dns-filter-couldnt-perform-reverse-lookup/230856/5 "2020-06-01T18:00:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
