# DNS lookup how to drop log filed if not resolved?

**URL:** <https://discuss.elastic.co/t/dns-lookup-how-to-drop-log-filed-if-not-resolved/194878>\
**Category:** Logstash\
**Created:** [August 12, 2019, 3:43pm UTC](https://discuss.elastic.co/t/dns-lookup-how-to-drop-log-filed-if-not-resolved/194878 "2019-08-12T15:43:24Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![iukea](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iukea/32/49083_2.png) [@iukea](https://discuss.elastic.co/u/iukea)\
**Post date:** [August 12, 2019, 3:43pm UTC](https://discuss.elastic.co/t/dns-lookup-how-to-drop-log-filed-if-not-resolved/194878/1 "2019-08-12T15:43:24Z")

</div>

Hello,

I am running logstash 6.8

I am taking all Src\_Ip addresses and doing a reverse DNS lookup through the DNS plugin in logstash.

Logstash YML

```auto
  if [src_ip] {
     
     
      mutate {
        add_field => {"DNS_Name" => "%{src_ip}"}
      }
      dns {
        reverse => ["DNS_Name"]
        action => "replace"
      }
  }

```

is there any way for if the IP address does not resolve back to a hostname for that field "DNS\_Name" to be blank?

example dropping the field names DNS field name from 31.184.249.177 because it is not resolving to anything.

![image](https://us1.discourse-cdn.com/elastic/original/3X/3/6/36c26c8baab8b31937d5be46434e85dccd49a4a9.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2019, 3:47pm UTC](https://discuss.elastic.co/t/dns-lookup-how-to-drop-log-filed-if-not-resolved/194878/2 "2019-08-12T15:47:37Z")

</div>

Compare the src\_ip and DNS\_Name fields and mutate the DNS\_Name if it is equal to the src\_ip?

---

<div class="post-metadata">

**Author:** ![iukea](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iukea/32/49083_2.png) [@iukea](https://discuss.elastic.co/u/iukea)\
**Post date:** [August 12, 2019, 4:18pm UTC](https://discuss.elastic.co/t/dns-lookup-how-to-drop-log-filed-if-not-resolved/194878/3 "2019-08-12T16:18:15Z")

</div>

could you give me an example of that. i am getting my butt handed to me by logstash

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2019, 4:23pm UTC](https://discuss.elastic.co/t/dns-lookup-how-to-drop-log-filed-if-not-resolved/194878/4 "2019-08-12T16:23:53Z")

</div>

The comparison would just be

```
if [src_ip] == [DNS_Name] {

```

If you want to delete the field then

```
mutate { remove_field => ["DNS_Name"] }

```

or if you want it to be an empty string

```
mutate { replace => { "DNS_Name" => "" } }
```

---

<div class="post-metadata">

**Author:** ![iukea](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iukea/32/49083_2.png) [@iukea](https://discuss.elastic.co/u/iukea)\
**Post date:** [August 12, 2019, 4:45pm UTC](https://discuss.elastic.co/t/dns-lookup-how-to-drop-log-filed-if-not-resolved/194878/5 "2019-08-12T16:45:38Z")

</div>

mmmmm

changed the yml to

```auto
 if [src_ip] == [DNS_Name] { 
     
     
      mutate {
        add_field => {"DNS_Name" => "%{src_ip}"}
      }
      mutate { replace => { "DNS_Name" => "" } }
      
      dns {
        reverse => ["DNS_Name"]
        action => "replace"
      }

    }

```

I now I think i broke it 😃  
Now it is just blanking out the DNS Name even when it can be resolved.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/0/b/0bec16bfa877fb213268e83e482c8fd9597cf241.png)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 12, 2019, 5:31pm UTC](https://discuss.elastic.co/t/dns-lookup-how-to-drop-log-filed-if-not-resolved/194878/6 "2019-08-12T17:31:31Z")

</div>

```
dns {
    reverse => ["DNS_Name"]
    action => "replace"
}
if [src_ip] == [DNS_Name] {
    mutate { replace => { "DNS_Name" => "" } }
}
```

---

<div class="post-metadata">

**Author:** ![iukea](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iukea/32/49083_2.png) [@iukea](https://discuss.elastic.co/u/iukea)\
**Post date:** [August 12, 2019, 7:02pm UTC](https://discuss.elastic.co/t/dns-lookup-how-to-drop-log-filed-if-not-resolved/194878/7 "2019-08-12T19:02:02Z")

</div>

You are a are a god!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 9, 2019, 7:02pm UTC](https://discuss.elastic.co/t/dns-lookup-how-to-drop-log-filed-if-not-resolved/194878/8 "2019-09-09T19:02:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
