# Elastic Agent, System Integration, Processors

**URL:** <https://discuss.elastic.co/t/elastic-agent-system-integration-processors/308236>\
**Category:** Kibana\
**Tags:** fleet\
**Created:** [June 27, 2022, 10:55am UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-processors/308236 "2022-06-27T10:55:45Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![fran\_hernandez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fran_hernandez/32/106728_2.png) [@fran\_hernandez](https://discuss.elastic.co/u/fran_hernandez)\
**Post date:** [June 27, 2022, 10:55am UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-processors/308236/1 "2022-06-27T10:55:45Z")

</div>

Hello,

I am trying to get the hostname of a given IP in a field (source.ip), I am doing this for an agent deployed within a system integration, I have defined some processors in the "processors" field some drop\_event.

But when I add the dns processor, the agent keeps updating in the log section and stops receiving events. But if I remove this, everything works again.

-DNS:  
type: reverse  
fields:  
source.ip: source.hostname

I've defined this in "Collect events from the windows event log -\> Security -\> Processors"

---

<div class="post-metadata">

**Author:** ![fran\_hernandez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fran_hernandez/32/106728_2.png) [@fran\_hernandez](https://discuss.elastic.co/u/fran_hernandez)\
**Post date:** [June 27, 2022, 11:11am UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-processors/308236/2 "2022-06-27T11:11:04Z")

</div>

PD:

If I type in the processors field the full configuration, everything works but I don't see the new field with the hostname and I don't see the label error in the document (tag\_on\_failure).

- dns:  
type: reverse  
action: append  
transport: tls  
fields:  
source.ip: source.hostname  
success\_cache:  
capacity.initial: 1000  
capacity.max: 10000  
min\_ttl: 1m  
failure\_cache:  
capacity.initial: 1000  
capacity.max: 10000  
ttl: 1m  
nameservers: ['192.168.202.2']  
timeout: 500ms  
tag\_on\_failure: [\_dns\_reverse\_lookup\_failed]

---

<div class="post-metadata">

**Author:** ![JLeysens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jleysens/32/67404_2.png) [@JLeysens](https://discuss.elastic.co/u/JLeysens)\
**Post date:** [June 27, 2022, 1:18pm UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-processors/308236/3 "2022-06-27T13:18:18Z")

</div>

> [@fran\_hernandez](#):
>
> source

Hi @fran_hernandez !

It is a bit tricky to help debug if we are not seeing a specific error when the pipeline is not working. Would it be possible for you to test the pipeline with example input and report back what error you are seeing.

You can use the simulate endpoint to do this:

> **[Simulate pipeline API | Elasticsearch Guide \[8.11\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/simulate-pipeline-api.html)**

---

<div class="post-metadata">

**Author:** ![fran\_hernandez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fran_hernandez/32/106728_2.png) [@fran\_hernandez](https://discuss.elastic.co/u/fran_hernandez)\
**Post date:** [June 28, 2022, 6:17am UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-processors/308236/4 "2022-06-28T06:17:32Z")

</div>

Hi! @JLeysens,

As I understand from the documentation, there is no processor in a pipeline to do this reverse DNS.

> **[Ingest processor reference | Elasticsearch Guide \[8.2\] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/processors.html)**

The Reverse DNS Processor is in the Filebeat documentation, if there is a way to do the Reverse DNS function using a pipeline in Elasticsearch, could you send me the docs?

Is there an agent or filebeat log file where I can see how filebeat processes the documents with the filters defined in the processors section?

Thank you!

---

<div class="post-metadata">

**Author:** ![JLeysens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jleysens/32/67404_2.png) [@JLeysens](https://discuss.elastic.co/u/JLeysens)\
**Post date:** [June 28, 2022, 12:04pm UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-processors/308236/5 "2022-06-28T12:04:27Z")

</div>

Ah my apologies, that is true there is no DNS lookup processor in ingest pipelines.

This might be silly, but are you correctly formatting your YML input:

```auto
processors:
  - dns:
      type: reverse
      fields:
        source.ip: source.hostname
        destination.ip: destination.hostname

```

You should be able to browse the package manifest here: [integrations/packages/windows at main · elastic/integrations · GitHub](https://github.com/elastic/integrations/tree/main/packages/windows#readme)

---

<div class="post-metadata">

**Author:** ![fran\_hernandez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fran_hernandez/32/106728_2.png) [@fran\_hernandez](https://discuss.elastic.co/u/fran_hernandez)\
**Post date:** [June 28, 2022, 12:26pm UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-processors/308236/6 "2022-06-28T12:26:26Z")

</div>

Yeah, I think it's formatted correctly, but here's a screenshot, just in case.

 ![Capture](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0dfe222e8a45265d4f0ca27d7fe022674cccd4e6.png)

I am doing this using system integration, not Windows.  
There is a strange behavior, because if I do the configuration that is in the screenshot, the agent stops logging, I need to specify the "nameservers" configuration and it starts working again, but it does not do any reverse function.

---

<div class="post-metadata">

**Author:** ![JLeysens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jleysens/32/67404_2.png) [@JLeysens](https://discuss.elastic.co/u/JLeysens)\
**Post date:** [June 28, 2022, 1:32pm UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-processors/308236/7 "2022-06-28T13:32:37Z")

</div>

OK I see.

We should be able to see agent logs in Kibana in Fleet - I was hoping you'd have seen something useful in there already:

> **[View Elastic Agent logs in Fleet | Fleet and Elastic Agent Guide \[7.17\] |...](https://www.elastic.co/guide/en/fleet/7.17/elastic-agent-logging.html#agent-view-log-events)**

We could try starting a standalone agent with your config (as a temporary workaround). Standalone agent logging is configured by setting something like:

```auto
agent:
  logging.level: info
  logging.to_files: true
  logging.files:
    path: /var/log/elastic-agent
    name: elastic-agent
    keepfiles: 7
    permissions: 0600

```

This will send agent logs to an ndjson file that you can look through.

* * *

As an aside, I thought we could debug by adding a test processor like:

```auto
  - add_fields:
      target: test
      fields:
        test: value

```

To ensure that our configurations are going through as we expect.

---

<div class="post-metadata">

**Author:** ![fran\_hernandez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fran_hernandez/32/106728_2.png) [@fran\_hernandez](https://discuss.elastic.co/u/fran_hernandez)\
**Post date:** [June 29, 2022, 6:45am UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-processors/308236/8 "2022-06-29T06:45:32Z")

</div>

Hi @JLeysens

I finally found the solution, all about adding fields and so it worked, nothing weird in the logging system so I started checking the index pipes, the final document fields are "post processors" fields. So the source.ip field doesn't work in this step.

If you put only the basic DNS settings, the agent stops logging in as I said, I added the nameservers to the config lines (everything started working again) and then I checked the "original fields", I mean the system in my case from the manifest of the package that I send.

So maybe I'll add this to the troubleshooting guide, the tag\_on\_failure function doesn't tag a wrong value from a wrong field. And if you don't specify the nameservers on the system against a Windows server that doesn't work, there is a "On Windows, you must always provide at least one nameserver" in the documentation. But I'll specify something like "windows event log" (just an idea).

Another thing that could be great is to attach the manifest to the documentation or specify that those fields are the fields that will work in the "pre-ingest pipelines" step.

So this is the working configuration:

```auto
-DNS:
    type: reverse
    fields:
      winlog.event_data.IpAddress: source.hostname
    nameservers: ['192.168.202.2']

```

Thanks for the support to a newbie!

---

<div class="post-metadata">

**Author:** ![JLeysens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jleysens/32/67404_2.png) [@JLeysens](https://discuss.elastic.co/u/JLeysens)\
**Post date:** [June 29, 2022, 8:49am UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-processors/308236/9 "2022-06-29T08:49:30Z")

</div>

No problem! Thanks for bearing with me.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2022, 8:50am UTC](https://discuss.elastic.co/t/elastic-agent-system-integration-processors/308236/10 "2022-07-27T08:50:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
