# DNS Filter wont work

**URL:** <https://discuss.elastic.co/t/dns-filter-wont-work/209094>\
**Category:** Logstash\
**Created:** [November 22, 2019, 4:34pm UTC](https://discuss.elastic.co/t/dns-filter-wont-work/209094 "2019-11-22T16:34:17Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticcp](https://avatars.discourse-cdn.com/v4/letter/e/90db22/32.png) [@elasticcp](https://discuss.elastic.co/u/elasticcp)\
**Post date:** [November 22, 2019, 4:34pm UTC](https://discuss.elastic.co/t/dns-filter-wont-work/209094/1 "2019-11-22T16:34:17Z")

</div>

**Hey i tried to resolve a hostname in to a DNS.**  
**My Input data Looks like this:**

```
> {
> "query_status": "ok",
> "urls": [
> {
> "id": "223622",
> "urlhaus_reference": "https:\/\/urlhaus.abuse.ch\/url\/223622\/",
> "url": "http:\/\/45.61.49.78\/razor\/r4z0r.mips",
> "url_status": "offline",
> "host": "45.61.49.78",
> "date_added": "2019-08-10 09:02:05 UTC",
> "threat": "malware_download",
> "blacklists": {
> "gsb": "not listed",
> "spamhaus_dbl": "not listed",
> "surbl": "not listed"
> },
> "reporter": "zbetcheckin",
> "larted": "true",
> "tags": [
> "elf"
> ]
> },
> {
> "id": "223621",
> "urlhaus_reference": "https:\/\/urlhaus.abuse.ch\/url\/223621\/",
> "url": "http:\/\/45.61.49.78\/razor\/r4z0r.sh4",
> "url_status": "offline",
> "host": "45.61.49.78",
> "date_added": "2019-08-10 09:02:03 UTC",
> "threat": "malware_download",
> "blacklists": {
> "gsb": "not listed",
> "spamhaus_dbl": "not listed",
> "surbl": "not listed"
> },
> "reporter": "zbetcheckin",
> "larted": "true",
> "tags": [
> "elf",
> "mirai"
> ]
> }
> ]
> }

```

**and my DNS filter.**

dns  
{  
resolve =\> ["[urls][host]"]  
action =\> "replace"

}

So what i want is to replace all Host names with a IP with the DNS Filter.  
For Example: "host" : "[eBay.com](http://eBay.com)" =\> "host" : "IP of the Host"  
I dont get a error message or whatever it just dont resolve all hosts.  
Maybe some of you know why not.

thank you

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 22, 2019, 5:57pm UTC](https://discuss.elastic.co/t/dns-filter-wont-work/209094/2 "2019-11-22T17:57:37Z")

</div>

> [@elasticcp](#):
>
> ```
> resolve => ["[urls][*][host]"]
> 
> ```

That will not work. The resolve option will accept an array of strings, but I think you are going to have to use ruby to build such an array. That will allow you to get an array of IP addresses, but does not modify the url field. You could write more ruby to do that.

---

<div class="post-metadata">

**Author:** ![elasticcp](https://avatars.discourse-cdn.com/v4/letter/e/90db22/32.png) [@elasticcp](https://discuss.elastic.co/u/elasticcp)\
**Post date:** [November 22, 2019, 6:27pm UTC](https://discuss.elastic.co/t/dns-filter-wont-work/209094/3 "2019-11-22T18:27:47Z")

</div>

Yes i think i could use a loop to iterate the Array and put the iterated value instead of "\*" …  
Where can i learn About ruby the best.  
Is logstash using Jruby or Ruby.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 22, 2019, 6:50pm UTC](https://discuss.elastic.co/t/dns-filter-wont-work/209094/4 "2019-11-22T18:50:15Z")

</div>

Actually there is a problem. You can build a list of hostnames using

```
    ruby {
        code => '
            hostlist = []
            u = event.get("urls")
            u.each_index { |x|
                hostlist << u[x]["host"]
            }
            event.set("hostlist", hostlist)
        '
    }

```

but there is no way to tell the dns filter to use it. It accepts fields that are arrays but only if they have a single entry. It will not iterate over the array.

If the urls field has a limited length you could use

```
    dns {
        resolve => ["[urls][0][host]", "[urls][1][host]", "[urls][2][host]"]
        action => "replace"
    }

```

but you will get a lot of noise in the logs from

```
[WARN][logstash.filters.dns][main] DNS filter could not resolve missing field {:field=>"[urls][2][host]"}
```

---

<div class="post-metadata">

**Author:** ![elasticcp](https://avatars.discourse-cdn.com/v4/letter/e/90db22/32.png) [@elasticcp](https://discuss.elastic.co/u/elasticcp)\
**Post date:** [November 22, 2019, 7:17pm UTC](https://discuss.elastic.co/t/dns-filter-wont-work/209094/5 "2019-11-22T19:17:09Z")

</div>

> [@Badger](#):
>
> hostlist =

The Array length is not over 1000 but it can be less.. but i think it is not a good idea to resolve all ip's separately like this

Is there Maybe a other way of resolving host names to IP'S, Maybe it is possible for ruby script without using Default DNS plugin

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 22, 2019, 7:35pm UTC](https://discuss.elastic.co/t/dns-filter-wont-work/209094/6 "2019-11-22T19:35:50Z")

</div>

I expect you could re-purpose the code from the dns filter.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2019, 7:35pm UTC](https://discuss.elastic.co/t/dns-filter-wont-work/209094/7 "2019-12-20T19:35:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
