# DNS filter not working

**URL:** <https://discuss.elastic.co/t/dns-filter-not-working/77315>\
**Category:** Logstash\
**Created:** [March 3, 2017, 1:11pm UTC](https://discuss.elastic.co/t/dns-filter-not-working/77315 "2017-03-03T13:11:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![nigdav007](https://avatars.discourse-cdn.com/v4/letter/n/e47774/32.png) [@nigdav007](https://discuss.elastic.co/u/nigdav007)\
**Post date:** [March 3, 2017, 1:11pm UTC](https://discuss.elastic.co/t/dns-filter-not-working/77315/1 "2017-03-03T13:11:45Z")

</div>

Hay all

I am an tad stuck with the DNS filter.

My issue all my syslogs hosts are coming up with the ip address and not the hostname.

I like to use the DNS filter to get the hostname, but for some reason its not working.

if i use this

> filter {  
> mutate {  
> add\_field =\> { "hostname" =\> "%{host}" }  
> }  
> dns {  
> action =\> "replace"  
> reverse =\> ["hostname"]  
> add\_tag =\> ["dns\_lookup"]  
> }

> }

I get logstash adding the host name field but nothing else

If i do this nothing happens at all

> filter {  
> dns {  
> add\_field =\> { "hostname" =\> "%{host}" }  
> action =\> "replace"  
> reverse =\> ["hostname"]  
> add\_tag =\> ["dns\_lookup"]  
> }

> }

Its like anything inside the DNS filter is being bypassed?

the version of logstash i am using is 5.2.0

Thanks in advance

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [March 3, 2017, 1:36pm UTC](https://discuss.elastic.co/t/dns-filter-not-working/77315/2 "2017-03-03T13:36:04Z")

</div>

Although the docs would lead one to believe that the name server used by the OS will be used by default by the DNS filter, the only way I have been able to make it work is by specifying a name server in the DNS filter config. The following works for me (logstash 5.0+)...

```
if [conn][dst_addr] {
    mutate {
        add_field => { "[conn][dst_hostname]" => "%{[conn][dst_addr]}"}
    }
    dns {
        reverse => ["[conn][dst_hostname]" ]
        action => "replace"
            
        # CUSTOMIZE THE FOLLOWING VALUES AS REQUIRED BY YOUR ENVIRONMENT!
        nameserver => ["192.168.255.1"]
        hit_cache_size => 4096
        hit_cache_ttl => 900
        failed_cache_size => 512
        failed_cache_ttl => 900
    }
}
```

---

<div class="post-metadata">

**Author:** ![nigdav007](https://avatars.discourse-cdn.com/v4/letter/n/e47774/32.png) [@nigdav007](https://discuss.elastic.co/u/nigdav007)\
**Post date:** [March 3, 2017, 2:02pm UTC](https://discuss.elastic.co/t/dns-filter-not-working/77315/3 "2017-03-03T14:02:35Z")

</div>

Hay Rcowart

thank for this i just tried and with no luck i changed your filter you gave me to this

filter {

```
mutate {
    add_field => { "hostname" => "%{host}"}
}
dns {
    reverse => ["hostname"]
    action => "replace"

    # CUSTOMIZE THE FOLLOWING VALUES AS REQUIRED BY YOUR ENVIRONMENT!
    nameserver => ["XX.X.X.X"]
    hit_cache_size => 4096
    hit_cache_ttl => 900
    failed_cache_size => 512
    failed_cache_ttl => 900
}

```

}

Can you see an issue with this config?

i also have and extra filter in the config, to just adds an new field what works

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [March 3, 2017, 2:35pm UTC](https://discuss.elastic.co/t/dns-filter-not-working/77315/4 "2017-03-03T14:35:33Z")

</div>

That looks good. In fact I have been using exactly that for months without issue.

It is possible that the DNS lookup is taking too long and timing out. Run this command...

```
curl -w '\nlookup time:\t%{time_namelookup}\n' -o /dev/null -s http://www.google.com

```

You will get an output like this...

```
lookup time:	0.066

```

This means the name lookup portion of fetching [www.google.com](http://www.google.com) took 0.066 seconds. The default timeout for the logstash DNS filter is 0.5 seconds. If your lookups are slower than that it will be as if the filter didn't work. If your DNS lookups are slow try changing the [timeout](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dns.html#plugins-filters-dns-timeout) option.

NOTE: If you are suffering from slow lookups you will need to figure out how speed things up, or reconsider using the DNS filter. Slow name lookups will dramatically slow overall event throughput.

Rob

---

<div class="post-metadata">

**Author:** ![astickler](https://avatars.discourse-cdn.com/v4/letter/a/53a042/32.png) [@astickler](https://discuss.elastic.co/u/astickler)\
**Post date:** [March 31, 2017, 1:29pm UTC](https://discuss.elastic.co/t/dns-filter-not-working/77315/5 "2017-03-31T13:29:42Z")

</div>

I have found that add\_field does not work as expected inside the dns filter. If the target field is referenced in the reverse/resolve option, then it will never appear in the event; if the target field is not referenced by resolve/reverse, it will appear in the event.

I think this partly explains NigelD's original post.  
Andrew

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 28, 2017, 1:29pm UTC](https://discuss.elastic.co/t/dns-filter-not-working/77315/6 "2017-04-28T13:29:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
