# Filter "logstash-filter-dns" doesn't work

**URL:** <https://discuss.elastic.co/t/filter-logstash-filter-dns-doesnt-work/139929>\
**Category:** Logstash\
**Created:** [July 13, 2018, 11:20am UTC](https://discuss.elastic.co/t/filter-logstash-filter-dns-doesnt-work/139929 "2018-07-13T11:20:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![da.frolov](https://avatars.discourse-cdn.com/v4/letter/d/cc9497/32.png) [@da.frolov](https://discuss.elastic.co/u/da.frolov)\
**Post date:** [July 13, 2018, 11:20am UTC](https://discuss.elastic.co/t/filter-logstash-filter-dns-doesnt-work/139929/1 "2018-07-13T11:20:03Z")

</div>

Hi, Amazing ElasticSearch Community!

English is my second language and I apologize in advance)))

I have a problem with filter in logstash "netflow.conf" file.

I collect the netflow data from my network devices, and I want to have the dns names src and dst hosts. I found that this can be done with plug-ins for logstash "filter-dns" and "filter-mutate". I installed these plugins and now I have this version:

```
localhost:/usr/share/logstash/bin# ./logstash-plugin list --verbose logstash-filter-dns
logstash-filter-dns (3.0.10)
localhost:/usr/share/logstash/bin# ./logstash-plugin list --verbose logstash-filter-mutate
logstash-filter-mutate (3.3.2)

```

I wrote the file netflow.conf and looks like this:

```
input {
     udp {
       port => 9996
       type => "netflow"
       codec => netflow {
         versions => [5,9,10]
       }
     }
}

filter{
 if [netflow][dst_addr] {
  mutate {
   add_field => { "[netflow][dst_hostname]" => "%{[netflow][dst_addr]}"}
  }
   dns {
    reverse => ["[netflow][dst_hostname]" ]
    action => "replace"
    nameserver => ["my dns server"]
    hit_cache_size => 4096
    hit_cache_ttl => 900
    failed_cache_size => 512
    failed_cache_ttl => 900
    }
  }
}

output {
 if [type] == "netflow" {
  elasticsearch {
     hosts => ["http://localhost:9200"]
     index => "netflow-%{+YYYY.MM.dd}"
     }
   }
}

```

But this configuration doesn't work((((

I checked that I have a normal server response time:

```
# curl -w '\nlookup time:\t%{time_namelookup}\n' -o /dev/null -s http://www.google.com
lookup time:	0.028513

```

In logs file i don't have any problems with filters.dns:

```
# cat /var/log/logstash/logstash-plain.log | grep filters.dns
#

```

Please help me somebody!

P.S. Netflow working perfect

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 10, 2018, 11:20am UTC](https://discuss.elastic.co/t/filter-logstash-filter-dns-doesnt-work/139929/2 "2018-08-10T11:20:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
