# DNS processor does not work with Suricata integration

**URL:** <https://discuss.elastic.co/t/dns-processor-does-not-work-with-suricata-integration/361961>\
**Category:** Elastic Agent\
**Tags:** integrations\
**Created:** [June 24, 2024, 12:54pm UTC](https://discuss.elastic.co/t/dns-processor-does-not-work-with-suricata-integration/361961 "2024-06-24T12:54:17Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![svatopluk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/svatopluk/32/122022_2.png) [@svatopluk](https://discuss.elastic.co/u/svatopluk)\
**Post date:** [June 24, 2024, 12:54pm UTC](https://discuss.elastic.co/t/dns-processor-does-not-work-with-suricata-integration/361961/1 "2024-06-24T12:54:17Z")

</div>

Hello community,  
I have a problem with dns processor. I am using Suricata integration and I need DNS reverse lookup, that's why I decided to use dns processor. I also created mapping for new fields. But this processor does not work. I have only empty fields without any error in logs and I don't know why? Please help me to fix it, thx.

Here is my written processor:

```auto
- dns:
   type: reverse
   action: replace
   transport: udp
   fields:
     suricata.eve.src_ip: source.hostname
     suricata.eve.dest_ip: destination.hostname
     source.ip: src.domain
     destination.ip: dest.domain
   nameservers: ['192.168.1.2']
   timeout: 500ms
   tag_on_failure: [_dns_reverse_lookup_failed]

```
