# Packetbeat-DNS index and template correction

**URL:** <https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [June 1, 2016, 6:36pm UTC](https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599 "2016-06-01T18:36:01Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [June 1, 2016, 6:36pm UTC](https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599/1 "2016-06-01T18:36:01Z")

</div>

HI all, I am struggling to get the correct information into Elasticsearch. I am using BIND DNS server running Packetbeats direct output to logstash, thereafter to elasticsearch and Kibana. The two fields that are causing some challenge are: dns.additionals and dns.authorities, the output look as follows respectively:  
dns.additionals {  
"class": "512",  
"data": "",  
"name": "",  
"ttl": 32768,  
"type": "OPT"  
}  
dns.answers {  
"class": "IN",  
"data": "23.214.151.174",  
"name": "[e1706.g.akamaiedge.net](http://e1706.g.akamaiedge.net)",  
"ttl": 19,  
"type": "A"  
}  
So it looks like there is a filed not split however not sure where the challenge is, in the logstash filter or the elasticsearch index template? Here is the configuration for logstash:  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

Any assistance will be truly appreciated.

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [June 1, 2016, 7:34pm UTC](https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599/2 "2016-06-01T19:34:52Z")

</div>

Here is an sample of a capture:  
{"@timestamp":"2016-06-01T18:29:57.514Z","beat":{"hostname":"BIND","name":"BIND"},"bytes\_in":64,"bytes\_out":222,"client\_ip":"192.168.88.250","client\_port":56458,"client\_proc":"","client\_server":"","count":1,"direction":"out","dns":{"additionals":[{"class":"512","data":"","name":"","ttl":32768,"type":"OPT"}],"additionals\_count":1,"answers":[{"class":"IN","data":"[geover-prod.dodsp.mp.microsoft.com.nsatc.net](http://geover-prod.dodsp.mp.microsoft.com.nsatc.net)","name":"[geover-prod.do.dsp.mp.microsoft.com](http://geover-prod.do.dsp.mp.microsoft.com)","ttl":3360,"type":"CNAME"},{"class":"IN","data":"[prod.do.dsp.mp.microsoft.com.edgekey.net](http://prod.do.dsp.mp.microsoft.com.edgekey.net)","name":"[geover-prod.dodsp.mp.microsoft.com.nsatc.net](http://geover-prod.dodsp.mp.microsoft.com.nsatc.net)","ttl":299,"type":"CNAME"},{"class":"IN","data":"[e1706.g.akamaiedge.net](http://e1706.g.akamaiedge.net)","name":"[prod.do.dsp.mp.microsoft.com.edgekey.net](http://prod.do.dsp.mp.microsoft.com.edgekey.net)","ttl":685,"type":"CNAME"},{"class":"IN","data":"23.214.151.174","name":"[e1706.g.akamaiedge.net](http://e1706.g.akamaiedge.net)","ttl":19,"type":"A"}],"answers\_count":4,"authorities\_count":0,"flags":{"authoritative":false,"recursion\_allowed":true,"recursion\_desired":true,"truncated\_response":false},"id":41071,"op\_code":"QUERY","question":{"class":"IN","name":"[geover-prod.do.dsp.mp.microsoft.com](http://geover-prod.do.dsp.mp.microsoft.com)","type":"A"},"response\_code":"NOERROR"},"ip":"8.8.8.8","method":"QUERY","port":53,"proc":"","query":"class IN, type A, [geover-prod.do.dsp.mp.microsoft.com](http://geover-prod.do.dsp.mp.microsoft.com)","resource":"[geover-prod.do.dsp.mp.microsoft.com](http://geover-prod.do.dsp.mp.microsoft.com)","responsetime":292,"server":"","status":"OK","transport":"udp","type":"dns"}

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 1, 2016, 8:34pm UTC](https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599/3 "2016-06-01T20:34:40Z")

</div>

Did you install the Elasticsearch index template provided with Packetbeat? See [https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-template.html](https://www.elastic.co/guide/en/beats/packetbeat/current/packetbeat-template.html)

Is your elasticsearch output in Logstash setup to write to the correct index with the correct type? See [https://www.elastic.co/guide/en/beats/libbeat/current/logstash-installation.html#logstash-setup](https://www.elastic.co/guide/en/beats/libbeat/current/logstash-installation.html#logstash-setup)

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [June 2, 2016, 5:23am UTC](https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599/4 "2016-06-02T05:23:36Z")

</div>

I have followed these guides and also removed the filter in logstash, however the sections are still not sorted in different fields. It looks like all information between the [] brackets are not filtered into separate fields e.g. [{"class":"512","data":"","name":"","ttl":32768,"type":"OPT"}]. in some of the responses there are also more than one response, is it possible to tag these items with e.g.  
currently:  
dns.additionals {  
"class": "512",  
"data": "",  
"name": "",  
"ttl": 32768,  
"type": "OPT"  
}

desired:  
dns.additionals.class 512  
dns.additionals.data  
[dns.additionals.name](http://dns.additionals.name)  
dns.additionals.ttl 32768  
dns.additionals.type OPT

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [June 2, 2016, 5:26am UTC](https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599/5 "2016-06-02T05:26:18Z")

</div>

Another example for the answer:  
dns.answers {  
"class": "IN",  
"data": "217.69.139.201",  
"name": "[mail.ru](http://mail.ru)",  
"ttl": 47,  
"type": "A"  
},  
{  
"class": "IN",  
"data": "94.100.180.200",  
"name": "[mail.ru](http://mail.ru)",  
"ttl": 47,  
"type": "A"  
},  
{  
"class": "IN",  
"data": "94.100.180.202",  
"name": "[mail.ru](http://mail.ru)",  
"ttl": 47,  
"type": "A"  
},  
{  
"class": "IN",  
"data": "217.69.139.202",  
"name": "[mail.ru](http://mail.ru)",  
"ttl": 47,  
"type": "A"  
}

so the same approach as above however to have the information in separate fields and to also be able to tag the dns.answers.data 217.69.139.201 with geoip information for each answar

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [June 2, 2016, 9:40pm UTC](https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599/6 "2016-06-02T21:40:03Z")

</div>

The [`dns.answers`](https://www.elastic.co/guide/en/beats/packetbeat/current/exported-fields-dns.html#_dns_answers) and [`dns.additions`](https://www.elastic.co/guide/en/beats/packetbeat/current/exported-fields-dns.html#_dns_authorities) fields are arrays because the DNS message allows there to be multiple responses.

There's not really any good way to flatten the array and store it (in what key would you place the data?). It sounds like the question that should be asked is how can Logstash be used to enrich an array of objects containing IP addresses with GeoIP information.

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [June 4, 2016, 4:04pm UTC](https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599/7 "2016-06-04T16:04:07Z")

</div>

Thank you very much for the feedback and suggestion, I have opened a request on the logstash section:

> [@Packetbeat logs filter DNS array fields](https://discuss.elastic.co/t/packetbeat-logs-filter-dns-array-fields/51858):
>
> Hi All, I have requests assistance in the Packetbeat forum initially however was referred to the logstash section for assistance. Here is the link for additional information if required on the prior discussion: [https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599](https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599) What I am doing is running packetbeat on the BIND DNS server, the logs are then running through logstash followed by elasticsearch and kibana respectively. The two array fields that are causing some challen…

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 22, 2016, 6:36pm UTC](https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599/8 "2016-06-22T18:36:01Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
