# DNS reverse, PTR in logstash

**URL:** <https://discuss.elastic.co/t/dns-reverse-ptr-in-logstash/28523>\
**Category:** Logstash\
**Created:** [September 2, 2015, 1:22pm UTC](https://discuss.elastic.co/t/dns-reverse-ptr-in-logstash/28523 "2015-09-02T13:22:13Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [September 2, 2015, 1:22pm UTC](https://discuss.elastic.co/t/dns-reverse-ptr-in-logstash/28523/1 "2015-09-02T13:22:13Z")

</div>

Hello, I would like to obtain the host name as a string instead of the IP.(make a DNS reverse or PTR) Could it be possible?  
This is my configuration filter\>  
mutate {  
rename =\> ["@host", "host"]  
}  
dns {  
reverse =\> ["host"]  
action =\> ["replace"]  
}  
Where is the problem? my logs always appears with the IP.  
Thank you  
best regards

---

<div class="post-metadata">

**Author:** ![billy6](https://avatars.discourse-cdn.com/v4/letter/b/cab0a1/32.png) [@billy6](https://discuss.elastic.co/u/billy6)\
**Post date:** [September 2, 2015, 2:07pm UTC](https://discuss.elastic.co/t/dns-reverse-ptr-in-logstash/28523/2 "2015-09-02T14:07:55Z")

</div>

Solved!!  
In CentOS machines logstash take the IPv6 address by default.  
It is necesary to write the IPv4 DNS address in  
nameserver =\> "XXX.XXX.XX.XX"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:30am UTC](https://discuss.elastic.co/t/dns-reverse-ptr-in-logstash/28523/3 "2017-07-06T05:30:20Z")

</div>


