following are configuration of packetbeat for Reverse DNS lookup
But i have no clarity what should i mention in below field
I have referring following document for same but its not giving clarity to me.
Can you please format your configuration using the
</> button so it's easier to tell how it is indented?
Which version of Packetbeat are you using?
dns processor with
type: reverse (currently the only supported type) will take a field whose value is an IP and perform a reverse DNS query to obtain the domain that resolves to that IP.
fields mapping here will take each source IP field (
client.ip in this example) and resolve each IP storing the resulting domain in the mapped field (
When you say it doesn't work, do you mean that the hostname fields are not being created, or are you getting an error?
This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.