# Packetbeat logs filter DNS array fields

**URL:** <https://discuss.elastic.co/t/packetbeat-logs-filter-dns-array-fields/51858>\
**Category:** Logstash\
**Created:** [June 4, 2016, 4:00pm UTC](https://discuss.elastic.co/t/packetbeat-logs-filter-dns-array-fields/51858 "2016-06-04T16:00:54Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [June 4, 2016, 4:00pm UTC](https://discuss.elastic.co/t/packetbeat-logs-filter-dns-array-fields/51858/1 "2016-06-04T16:00:54Z")

</div>

Hi All, I have requests assistance in the Packetbeat forum initially however was referred to the logstash section for assistance. Here is the link for additional information if required on the prior discussion:

> [@Packetbeat-DNS index and template correction](https://discuss.elastic.co/t/packetbeat-dns-index-and-template-correction/51599):
>
> HI all, I am struggling to get the correct information into Elasticsearch. I am using BIND DNS server running Packetbeats direct output to logstash, thereafter to elasticsearch and Kibana. The two fields that are causing some challenge are: dns.additionals and dns.authorities, the output look as follows respectively: dns.additionals { "class": "512", "data": "", "name": "", "ttl": 32768, "type": "OPT" } dns.answers { "class": "IN", "data": "23.214.151.174", "name": "[e1706.g.…](http://e1706.g.akamaiedge.net)

What I am doing is running packetbeat on the BIND DNS server, the logs are then running through logstash followed by elasticsearch and kibana respectively. The two array fields that are causing some challenge are: dns.additionals and dns.authorities, the output look as follows respectively:  
dns.additionals {  
"class": "512",  
"data": "",  
"name": "",  
"ttl": 32768,  
"type": "OPT"  
}  
dns.answers {  
"class": "IN",  
"data": "23.214.151.174",  
"name": "[e1706.g.akamaiedge.net](http://e1706.g.akamaiedge.net)",  
"ttl": 19,  
"type": "A"  
}

It looks like all information between the brackets are not filtered into separate fields e.g. [{"class":"512","data":"","name":"","ttl":32768,"type":"OPT"}]. in some of the responses there are also more than one response, is it possible to tag these items with e.g.  
currently:  
dns.additionals {  
"class": "512",  
"data": "",  
"name": "",  
"ttl": 32768,  
"type": "OPT"  
}

desired:  
dns.additionals.class 512  
dns.additionals.data  
dns.additionals.name  
dns.additionals.ttl 32768  
dns.additionals.type OPT

Another example for the answer:  
dns.answers {  
"class": "IN",  
"data": "217.69.139.201",  
"name": "[mail.ru](http://mail.ru)",  
"ttl": 47,  
"type": "A"  
},  
{  
"class": "IN",  
"data": "94.100.180.200",  
"name": "[mail.ru](http://mail.ru)",  
"ttl": 47,  
"type": "A"  
},  
{  
"class": "IN",  
"data": "94.100.180.202",  
"name": "[mail.ru](http://mail.ru)",  
"ttl": 47,  
"type": "A"  
},  
{  
"class": "IN",  
"data": "217.69.139.202",  
"name": "[mail.ru](http://mail.ru)",  
"ttl": 47,  
"type": "A"  
}

so the same approach as above however to have the information in separate fields and to also be able to tag the dns.answers.data 217.69.139.201 with geoip information for each answer

---

<div class="post-metadata">

**Author:** ![Hans](https://avatars.discourse-cdn.com/v4/letter/h/e19b73/32.png) [@Hans](https://discuss.elastic.co/u/Hans)\
**Post date:** [June 7, 2016, 9:53am UTC](https://discuss.elastic.co/t/packetbeat-logs-filter-dns-array-fields/51858/2 "2016-06-07T09:53:02Z")

</div>

Can Logstash filters handle the array fields or should this be done elsewhere?.

---

<div class="post-metadata">

**Author:** ![gjt](https://avatars.discourse-cdn.com/v4/letter/g/f4b2a3/32.png) [@gjt](https://discuss.elastic.co/u/gjt)\
**Post date:** [July 3, 2017, 3:40pm UTC](https://discuss.elastic.co/t/packetbeat-logs-filter-dns-array-fields/51858/3 "2017-07-03T15:40:55Z")

</div>

Hi Hans, did you ever find a solution to this? We are facing the exact same issue  
Thanks  
G

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 4:21am UTC](https://discuss.elastic.co/t/packetbeat-logs-filter-dns-array-fields/51858/4 "2022-11-04T04:21:58Z")

</div>


