# How to split DNS request and retrive the domain

**URL:** <https://discuss.elastic.co/t/how-to-split-dns-request-and-retrive-the-domain/97074>\
**Category:** Logstash\
**Created:** [August 15, 2017, 8:38am UTC](https://discuss.elastic.co/t/how-to-split-dns-request-and-retrive-the-domain/97074 "2017-08-15T08:38:12Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![mikygee](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@mikygee](https://discuss.elastic.co/u/mikygee)\
**Post date:** [August 15, 2017, 8:38am UTC](https://discuss.elastic.co/t/how-to-split-dns-request-and-retrive-the-domain/97074/1 "2017-08-15T08:38:12Z")

</div>

Hello,

I've got a configuration that seems to work fine

```
filter {
  if [program] == "named" {
    grok {
        break_on_match => true
        patterns_dir => "/etc/logstash/conf.d/patterns"
        match => ["message", "%{BIND9}"]
        tag_on_failure => ["named_parsing_failed"]
        remove_tag => ["_grokparsefailure"]
        add_tag => ["DNS"]
    }
  }
}
---
BIND9 client (%{IPV4:dns_client_ip})#(%{NONNEGINT:dns_uuid})?.*query: (%{HOSTNAME:dns_dest}) (%{WORD:dns_type}) (%{WORD:dns_record})?.*\((%{IPV4:dns_server})\)

```

But ! retrieve the field dns\_dest = [play.google.com](http://play.google.com) and I would like to isolate the domain [google.com](http://google.com)  
I'd prefer not to touch the grok pattern and keep dns\_dest, and using it thereafter to extract the domain.

How should I do that ?

Thank you

---

<div class="post-metadata">

**Author:** ![mikygee](https://avatars.discourse-cdn.com/v4/letter/m/57b2e6/32.png) [@mikygee](https://discuss.elastic.co/u/mikygee)\
**Post date:** [August 17, 2017, 11:46am UTC](https://discuss.elastic.co/t/how-to-split-dns-request-and-retrive-the-domain/97074/2 "2017-08-17T11:46:49Z")

</div>

I've tried to insert a new grok stanza but it doesn't work. In my test I just try to extract the tld field

```
filter {
  if [program] == "named" {
    grok {
        break_on_match => true
        patterns_dir => "/etc/logstash/conf.d/patterns"
        match => ["message", "%{BIND9}"]

    grok {
      match => ["dns_record", ".*\.%{WORD:tld}$"]
    }

        tag_on_failure => ["named_parsing_failed"]
        remove_tag => ["_grokparsefailure"]
        add_tag => ["DNS"]
    }
  }
}

```

Should I use grok ? or kv ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 14, 2017, 11:47am UTC](https://discuss.elastic.co/t/how-to-split-dns-request-and-retrive-the-domain/97074/3 "2017-09-14T11:47:01Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
