# DNS plugin and new field

**URL:** <https://discuss.elastic.co/t/dns-plugin-and-new-field/235212>\
**Category:** Logstash\
**Created:** [June 1, 2020, 5:29pm UTC](https://discuss.elastic.co/t/dns-plugin-and-new-field/235212 "2020-06-01T17:29:36Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![kernelpanic](https://avatars.discourse-cdn.com/v4/letter/k/c89c15/32.png) [@kernelpanic](https://discuss.elastic.co/u/kernelpanic)\
**Post date:** [June 1, 2020, 5:29pm UTC](https://discuss.elastic.co/t/dns-plugin-and-new-field/235212/1 "2020-06-01T17:29:37Z")

</div>

Hello, we're using the ElasticStack 7.6.1 and I was wondering how to get the DNS filter for Logstash to perform a reverse DNS lookup on the IP address in each each message and put the results in a new field; looking at the documentation I can only see append or replace as the action.

Any help greatly appreciated.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 1, 2020, 5:55pm UTC](https://discuss.elastic.co/t/dns-plugin-and-new-field/235212/2 "2020-06-01T17:55:30Z")

</div>

> [@kernelpanic](#):
>
> I was wondering how to get the DNS filter for Logstash to perform a reverse DNS lookup on the IP address in each each message and put the results in a new field

The dns filter always modifies the field used to tell it what to reverse/resolve. It does not have a target option.

You can use mutate to copy the field you want to reverse lookup to a new field, then use the dns filter to overwrite that. Then possibly remove the new field if the lookup failed and it is still equal to the address value.

---

<div class="post-metadata">

**Author:** ![kernelpanic](https://avatars.discourse-cdn.com/v4/letter/k/c89c15/32.png) [@kernelpanic](https://discuss.elastic.co/u/kernelpanic)\
**Post date:** [June 2, 2020, 8:58am UTC](https://discuss.elastic.co/t/dns-plugin-and-new-field/235212/3 "2020-06-02T08:58:02Z")

</div>

Thanks Badger that sounds like a plan

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2020, 8:58am UTC](https://discuss.elastic.co/t/dns-plugin-and-new-field/235212/4 "2020-06-30T08:58:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
