# Gork fpr the DNS qureu log

**URL:** <https://discuss.elastic.co/t/gork-fpr-the-dns-qureu-log/193331>\
**Category:** Logstash\
**Created:** [August 1, 2019, 1:34pm UTC](https://discuss.elastic.co/t/gork-fpr-the-dns-qureu-log/193331 "2019-08-01T13:34:50Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![unicxs\_support](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/unicxs_support/32/46602_2.png) [@unicxs\_support](https://discuss.elastic.co/u/unicxs_support)\
**Post date:** [August 1, 2019, 1:34pm UTC](https://discuss.elastic.co/t/gork-fpr-the-dns-qureu-log/193331/1 "2019-08-01T13:34:51Z")

</div>

Hello Experts,

I've below logstream data which indeed a DNS query data where i have a literal dot after `view external: query:` which usually referred to be an IP address or a domain address but here its coming as dot for some cases which is been presented as `null` whereas i want this to be stored into a variable which later can be seen as a literal dot `.` in the Kibana dashboard.

> 30-Jul-2019 22:35:19.766 queries: info: client 192.6.11.5#44401: view external: query: . IN A + (192.140.1.6) **\<-- this the log which has dot**

> 31-Jul-2019 22:30:03.278 queries: info: client 192.6.11.5#42899: view external: query: [api.zhuti.intl.xiaomi.com](http://api.zhuti.intl.xiaomi.com) IN A +ED (192.140.1.6) **\<-- this is usual log stream**

Below is the grok i'm using to parse the above log, indeed i'm looking for the gork which can work for both the pattern of logs.

```
%{MONTHDAY:day}-%{MONTH:month}-%{YEAR:year} %{TIME:time} queries: info: client %{IPV4:internal_dns}#%{INT:srcport}:%{DATA}:%{SPACE}%{WORD}:%{SPACE}(?:%{HOSTNAME:Client_Address}|(.*)) %{DATA:querytpe1} %{DATA:querytype2} %{DATA:querytype3} %{SPACE}\(%{IPV4:external_dns}\)

```

Please Suggest.

Thanks for the help in Advanced,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 1, 2019, 1:56pm UTC](https://discuss.elastic.co/t/gork-fpr-the-dns-qureu-log/193331/2 "2019-08-01T13:56:52Z")

</div>

Use

```
(?:%{HOSTNAME:Client_Address}|(?<Client_Address>\.))
```

---

<div class="post-metadata">

**Author:** ![unicxs\_support](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/unicxs_support/32/46602_2.png) [@unicxs\_support](https://discuss.elastic.co/u/unicxs_support)\
**Post date:** [August 1, 2019, 3:44pm UTC](https://discuss.elastic.co/t/gork-fpr-the-dns-qureu-log/193331/3 "2019-08-01T15:44:16Z")

</div>

Thanks @Badger , sorry for the confusion, i just tested and saw the below gork expression Just works fine for both the psotes logs.

```
%{MONTHDAY:day}-%{MONTH:month}-%{YEAR:year} %{TIME:time} queries: info: client %{IPV4:internal_dns}#%{INT:srcport}:%{DATA}:%{SPACE}%{WORD}:%{SPACE} %{DATA:querytpe1} %{DATA:querytype2} %{DATA:querytype3} %{SPACE}\(%{IPV4:external_dns}\)
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 29, 2019, 3:44pm UTC](https://discuss.elastic.co/t/gork-fpr-the-dns-qureu-log/193331/4 "2019-08-29T15:44:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
