# Filebeat haproxy with dns processor

**URL:** <https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 11, 2022, 7:43pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501 "2022-05-11T19:43:05Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [May 11, 2022, 7:43pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501/1 "2022-05-11T19:43:05Z")

</div>

I have succssfully send haproxy log to Elasticsearch using filebeat.  
next step I am trying to do is to change destination.ip and source.ip to name

but I don't think I am using dns processor correctly. I am not getting this source.hostname field.  
I do get source.ip field. dns servers are correct. I can resolve the IP to name from prompt on same machine.

what am I doing wrong?

here is my haproxy.yml file

```auto
- module: haproxy
  # All logs
  log:
    enabled: true

    # Set which input to use between syslog (default) or file.
    var.input: "file"

    # Set custom paths for the log files. If left empty,
    # Filebeat will choose the paths depending on your OS.
    var.paths: ["/var/log/haproxy-traffic.log"]

  processors:
  - dns:
      type: reverse
       fields:
          source.ip: source.hostname
       nameservers: ['10.59.240.246', '10.167.17.40']
       timeout: 5000ms
       tag_on_failure: [_dns_reverse_lookup_failed]

```

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 12, 2022, 12:30am UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501/2 "2022-05-12T00:30:58Z")

</div>

What version of filebeat? I'm pretty sure the source.ip field doesn't exist yet as most of the processing exists within the Elasticsearch ingest pipelines, not filebeat.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [May 12, 2022, 3:58pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501/3 "2022-05-12T15:58:03Z")

</div>

Version 7.17.1  
yes source.ip exist I can see it in discover.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 12, 2022, 4:20pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501/4 "2022-05-12T16:20:07Z")

</div>

Yes but its being created in Elasticsearch, after leaving filebeat so the filebeat processor won't work.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [May 12, 2022, 8:47pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501/5 "2022-05-12T20:47:01Z")

</div>

no it is not being created in Elasticsearch.

this is part of the metric that haproxy log has  
and I want to convert or add source.name as source.ip is coming from log file.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 12, 2022, 9:04pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501/6 "2022-05-12T21:04:07Z")

</div>

You misunderstand, the log from HAProxy isn't parsed into individual fields until it reaches Elasticsearch. Here is the grok processor in the ingest pipeline that does it, [beats/pipeline.yml at v7.17.1 · elastic/beats · GitHub](https://github.com/elastic/beats/blob/v7.17.1/filebeat/module/haproxy/log/ingest/pipeline.yml#L7). `source.ip` isn't created until [beats/pipeline.yml at v7.17.1 · elastic/beats · GitHub](https://github.com/elastic/beats/blob/v7.17.1/filebeat/module/haproxy/log/ingest/pipeline.yml#L73). When u add the processor to filebeat it fails because `source.ip` field doesn't exist yet.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [May 16, 2022, 1:04pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501/7 "2022-05-16T13:04:50Z")

</div>

ohhh now i see what you mean.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [May 16, 2022, 6:02pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501/8 "2022-05-16T18:02:12Z")

</div>

how do I convert that yml file to ingest pipeline?

is there a simple command that convert whole thing?

[https://github.com/elastic/beats/blob/v7.17.1/filebeat/module/haproxy/log/ingest/pipeline.yml#L7](https://github.com/elastic/beats/blob/v7.17.1/filebeat/module/haproxy/log/ingest/pipeline.yml#L7)

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 17, 2022, 12:03pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501/9 "2022-05-17T12:03:20Z")

</div>

What do u mean? When u enable the module and run the setup command, it gets loaded into Elasticsearch for you.

---

<div class="post-metadata">

**Author:** ![elasticforme](https://avatars.discourse-cdn.com/v4/letter/e/f05b48/32.png) [@elasticforme](https://discuss.elastic.co/u/elasticforme)\
**Post date:** [May 17, 2022, 12:56pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501/10 "2022-05-17T12:56:47Z")

</div>

yes I found it. Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 14, 2022, 2:57pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-with-dns-processor/304501/11 "2022-06-14T14:57:46Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
