# Filebeat processor for single line logs?

**URL:** <https://discuss.elastic.co/t/filebeat-processor-for-single-line-logs/242812>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 27, 2020, 10:10pm UTC](https://discuss.elastic.co/t/filebeat-processor-for-single-line-logs/242812 "2020-07-27T22:10:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![t3fsx](https://avatars.discourse-cdn.com/v4/letter/t/bc79bd/32.png) [@t3fsx](https://discuss.elastic.co/u/t3fsx)\
**Post date:** [July 27, 2020, 10:10pm UTC](https://discuss.elastic.co/t/filebeat-processor-for-single-line-logs/242812/1 "2020-07-27T22:10:34Z")

</div>

I ran into this threat in Github so I just copy-paste:

- Steps to Reproduce: Enable Apache module in Filebeat and use the DNS processor; configuration example below:

```auto
- dns:
    type: reverse
    action: append
    fields:
      source.ip: source.hostname
      destination.ip: destination.hostname
    success_cache:
      capacity.initial: 1000
      capacity.max: 10000
    failure_cache:
      capacity.initial: 1000
      capacity.max: 10000
      ttl: 1m
    nameservers: ['8.8.8.8', '8.8.4.4']
    timeout: 500ms
    tag_on_failure: [_dns_reverse_lookup_failed]

```

In my particular case I'm also using other processors, namely the `add_fields` processor. While that processor works, DNS silently fails.

There will be no `source.hostname` or `destination.hostname` in the http events dispatched to Elasticseach.

On a second thought I've noticed that this is not working for the `auth` module either, which leads me to believe that the DNS processor will not work on single line logs like Apache and SSH.

It's possible that this is related to the order in which the processor is ran. If it happens _after_ the Filebeat pipeline transforms that single line log to ECS-mapped event, it should work (as the fields configured in the DNS processor are present), but if it happens before then it's not expected to work, as those single line logs don't hold any `field:value` schema.

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [July 28, 2020, 8:10am UTC](https://discuss.elastic.co/t/filebeat-processor-for-single-line-logs/242812/2 "2020-07-28T08:10:08Z")

</div>

Did you try to enable debug logging?

---

<div class="post-metadata">

**Author:** ![t3fsx](https://avatars.discourse-cdn.com/v4/letter/t/bc79bd/32.png) [@t3fsx](https://discuss.elastic.co/u/t3fsx)\
**Post date:** [July 29, 2020, 9:30pm UTC](https://discuss.elastic.co/t/filebeat-processor-for-single-line-logs/242812/3 "2020-07-29T21:30:54Z")

</div>

No, mostly because I wanted to understand if what i want to do is possible or no. is filebeat able to use the dns processor for Apache, for exanple?

If so and not working i can troubleshot more.

---

<div class="post-metadata">

**Author:** ![mtojek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mtojek/32/63863_2.png) [@mtojek](https://discuss.elastic.co/u/mtojek)\
**Post date:** [July 30, 2020, 7:10am UTC](https://discuss.elastic.co/t/filebeat-processor-for-single-line-logs/242812/4 "2020-07-30T07:10:24Z")

</div>

> Is filebeat able to use the dns processor for Apache, for example?

yes, it's available and described here: [DNS Reverse Lookup | Filebeat Reference [master] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/master/processor-dns.html) I don't expect any interference between processors. Please recheck your configuration.

---

<div class="post-metadata">

**Author:** ![t3fsx](https://avatars.discourse-cdn.com/v4/letter/t/bc79bd/32.png) [@t3fsx](https://discuss.elastic.co/u/t3fsx)\
**Post date:** [July 31, 2020, 1:03am UTC](https://discuss.elastic.co/t/filebeat-processor-for-single-line-logs/242812/5 "2020-07-31T01:03:21Z")

</div>

I even copy paste the configuration above. it doesn't work. you can try for yourself. use dns processor and enable apache module. it will not work. try ssh module. it will not work.

processor doesnt pick none of them. if you try suricata. works.

---

<div class="post-metadata">

**Author:** ![t3fsx](https://avatars.discourse-cdn.com/v4/letter/t/bc79bd/32.png) [@t3fsx](https://discuss.elastic.co/u/t3fsx)\
**Post date:** [July 31, 2020, 9:30pm UTC](https://discuss.elastic.co/t/filebeat-processor-for-single-line-logs/242812/6 "2020-07-31T21:30:42Z")

</div>

Is ther docs that explain order of processors?

is

source -\> ecs -\> processor?  
source -\> processor -\> ecs?

processor doesnt work on modules apache and ssh and docs dont help.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [August 24, 2020, 4:24pm UTC](https://discuss.elastic.co/t/filebeat-processor-for-single-line-logs/242812/7 "2020-08-24T16:24:15Z")

</div>

Unfortunately, you cannot use the DNS processor like this with the Apache module. The fields `source.ip` and `destination.ip` are extracted from the log lines on Elasticsearch. Thus, when Filebeat tries to run the DNS processor, it cannot do anything, as those fields do not exist at that point of processing.

DNS processor can only work if you add the fields to the event beforehand.

```auto
processors:
- add_fields:
  source.ip: 1.2.3.4
- dns:
  your_dns_config

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 21, 2020, 6:24pm UTC](https://discuss.elastic.co/t/filebeat-processor-for-single-line-logs/242812/8 "2020-09-21T18:24:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
