# How to drop DNS event if they are present into top 1 million file

**URL:** <https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981>\
**Category:** Logstash\
**Created:** [November 15, 2022, 4:43pm UTC](https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981 "2022-11-15T16:43:11Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![yquirion](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yquirion/32/107068_2.png) [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Post date:** [November 15, 2022, 4:43pm UTC](https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981/1 "2022-11-15T16:43:11Z")

</div>

Dear all,

I'm wonderion how to configure a logstash pipeline that will handle my DNS logs. From that logs, there are lots of logs I don't want to see because I know they are legitimate.

So I would like to have logstash looking into the Top One Million file ([Cisco Popularity List](http://s3-us-west-1.amazonaws.com/umbrella-static/index.html)) and drop all domains that are matching this file.

The file has the following format:

```auto
1,google.com
2,www.google.com
3,microsoft.com
4,netflix.com
5,data.microsoft.com
6,cloud.netflix.com
7,prod.cloud.netflix.com
8,ftl.netflix.com
9,prod.ftl.netflix.com
10,nrdp.prod.cloud.netflix.com

```

The file is pretty huge, and I would like to have it very performant. Our DNS is sending more than 1k events by seconds, so it needs to be very powerfull.

Does someone has an idea how to configure this with logstash?

Thank you and best regards,  
Yanick

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 15, 2022, 6:52pm UTC](https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981/2 "2022-11-15T18:52:48Z")

</div>

I would reorder the columns so that the domain name comes first, then use a translate filter to do the lookup, and drop {} the event if it gets a match.

---

<div class="post-metadata">

**Author:** ![yquirion](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yquirion/32/107068_2.png) [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Post date:** [November 15, 2022, 8:48pm UTC](https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981/3 "2022-11-15T20:48:17Z")

</div>

Hi Badger!

Thank you very much for your answer.

I look into the translate plugin, but I can't see any "drop" function to be used with the translate.

Should I, for example, use _add\_tag_ to add a specific tag on sucessfull match then use drop{} when that specific tag is present to drop the event?

Thanks!  
Yanick

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 15, 2022, 9:05pm UTC](https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981/4 "2022-11-15T21:05:31Z")

</div>

You can use the target option to tell the translate where to write the looked up value

```
target => "[@metadata][lookup]"

```

then test whether it exists

```
if [@metadata][lookup] { drop {} }

```

Doing it using the add\_tag option would likely also work.

---

<div class="post-metadata">

**Author:** ![yquirion](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/yquirion/32/107068_2.png) [@yquirion](https://discuss.elastic.co/u/yquirion)\
**Post date:** [November 16, 2022, 4:01pm UTC](https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981/5 "2022-11-16T16:01:32Z")

</div>

Hi Badger,

It is working fine. The question I have, do you think that dictinnary file, who contains 1M lines can slow down my logstash servers? So far, we only add the secondary DNS server and everything is responding just fine, but when I will add the primary DNS server, this one has 3-4 time more requests by seconds.

Thank you again for your help. I was looking to someting different before you siggest me the `translate` plugin. I tought there was other plugins that can read CSV file.

Regards,  
Yanick

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [November 16, 2022, 4:55pm UTC](https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981/6 "2022-11-16T16:55:32Z")

</div>

The dictionary that translate uses is basically a Ruby hash, and the performance of that should not significantly decline as the number of entries increases.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 14, 2022, 4:55pm UTC](https://discuss.elastic.co/t/how-to-drop-dns-event-if-they-are-present-into-top-1-million-file/318981/7 "2022-12-14T16:55:54Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
