# How to use custom field in dns filter?

**URL:** <https://discuss.elastic.co/t/how-to-use-custom-field-in-dns-filter/169809>\
**Category:** Logstash\
**Created:** [February 25, 2019, 11:17am UTC](https://discuss.elastic.co/t/how-to-use-custom-field-in-dns-filter/169809 "2019-02-25T11:17:26Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Wind2dk](https://avatars.discourse-cdn.com/v4/letter/w/67e7ee/32.png) [@Wind2dk](https://discuss.elastic.co/u/Wind2dk)\
**Post date:** [February 25, 2019, 11:17am UTC](https://discuss.elastic.co/t/how-to-use-custom-field-in-dns-filter/169809/1 "2019-02-25T11:17:26Z")

</div>

I'm working on a filter to resolve hostnames in ip fields. Since there is multiple ip fields, i've added a metadata field, that i can later use to resolve the actual field.

If i use resolve =\> "ip\_field\_1" it correctly resolves the hostname to an ip, but when i try to use the value from the field, it fails to resolve the hostname.

filter {  
mutate { add\_field =\> { "[@metadata][ip\_field]" =\> "ip\_field\_1" } }

if [@metadata][ip\_field] {  
dns {  
nameserver =\> ["8.8.8.8"]  
resolve =\> ["[@metadata][ip\_field]" ]  
action =\> "replace"  
hit\_cache\_ttl =\> 3540  
hit\_cache\_size =\> 1000000  
failed\_cache\_ttl =\> 10  
failed\_cache\_size =\> 1000000  
timeout =\> 2  
}  
}  
}

Added after edit:  
What i want to accomplish is the following without using 100 lines of code..

filter {  
if [ip\_field\_1] {  
dns {  
nameserver =\> ["8.8.8.8"]  
resolve =\> "ip\_field\_1"  
action =\> "replace"  
hit\_cache\_ttl =\> 3540  
hit\_cache\_size =\> 1000000  
failed\_cache\_ttl =\> 10  
failed\_cache\_size =\> 1000000  
timeout =\> 2  
}  
}  
if [ip\_field\_2] {  
dns {  
nameserver =\> ["8.8.8.8"]  
resolve =\> "ip\_field\_2"  
action =\> "replace"  
hit\_cache\_ttl =\> 3540  
hit\_cache\_size =\> 1000000  
failed\_cache\_ttl =\> 10  
failed\_cache\_size =\> 1000000  
timeout =\> 2  
}  
}  
if [ip\_field\_3] {  
.....  
}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 25, 2019, 1:55pm UTC](https://discuss.elastic.co/t/how-to-use-custom-field-in-dns-filter/169809/2 "2019-02-25T13:55:26Z")

</div>

logstash does not support this kind of indirection. But you could something like this to copy the field to a fixed field name.

```
    ruby {
        code => '
            fieldname = event.get("[@metadata][ip_field]")
            if fieldname then
                fieldvalue = event.get(fieldname)
                if fieldvalue then
                    event.set("[@metadata][ip]", fieldvalue)
                end
            end
        '
    }
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 25, 2019, 1:55pm UTC](https://discuss.elastic.co/t/how-to-use-custom-field-in-dns-filter/169809/3 "2019-03-25T13:55:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
