# Supplement vlan.id to DNS data

**URL:** <https://discuss.elastic.co/t/supplement-vlan-id-to-dns-data/328453>\
**Category:** Beats\
**Tags:** packetbeat\
**Created:** [March 24, 2023, 11:37am UTC](https://discuss.elastic.co/t/supplement-vlan-id-to-dns-data/328453 "2023-03-24T11:37:25Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![infofs](https://avatars.discourse-cdn.com/v4/letter/i/e19b73/32.png) [@infofs](https://discuss.elastic.co/u/infofs)\
**Post date:** [March 24, 2023, 11:37am UTC](https://discuss.elastic.co/t/supplement-vlan-id-to-dns-data/328453/1 "2023-03-24T11:37:25Z")

</div>

I am sending all DNS traffic to logstash. Is it possible to add vlan data (especially the vlan.id) to this output?  
This is my packetbeat.yml:

```auto
# =============================== Network device ===============================
packetbeat.interfaces.device: any
packetbeat.interfaces.type: af_packet

packetbeat.interfaces.internal_networks:
  - private

# =========================== Transaction protocols ============================
packetbeat.protocols:
- type: dns
  ports: [53]

# ================================== General ===================================
name: <servername>

tags: [forwarded]

# ================================== Outputs ===================================

# ------------------------------ Logstash Output -------------------------------
output.logstash:
  # The Logstash hosts
  hosts: ["<dip>:<dport>"]

# ================================= Processors =================================
processors:
  - # Add forwarded to tags when processing data from a network tap or mirror.
    if.contains.tags: forwarded
    then:
      - drop_fields:
          fields: [host]
    else:
      - add_host_metadata: ~
  - add_cloud_metadata: ~
  - add_docker_metadata: ~
  - detect_mime_type:
      field: http.request.body.content
      target: http.request.mime_type
  - detect_mime_type:
      field: http.response.body.content
      target: http.response.mime_type

```

btw, is it possible to define more than one device on which packetbeat listens to (without using 'any')?

---

<div class="post-metadata">

**Author:** ![andrewkroh](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrewkroh/32/3784_2.png) [@andrewkroh](https://discuss.elastic.co/u/andrewkroh)\
**Post date:** [March 24, 2023, 2:06pm UTC](https://discuss.elastic.co/t/supplement-vlan-id-to-dns-data/328453/2 "2023-03-24T14:06:11Z")

</div>

It does not report the vlan ID for decoded protocol data like DNS. It should be possible to add this since it can see the 802.1q header (although I found this one old issue that might be the reason why it was never added [Packetbeat: af\_packet doesn't report VLAN ID · Issue #12794 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/12794)).

I recommend to open a request on github to add this feature. We have the `network.vlan.id` field in Elastic Common Schema to hold this data.

---

<div class="post-metadata">

**Author:** ![infofs](https://avatars.discourse-cdn.com/v4/letter/i/e19b73/32.png) [@infofs](https://discuss.elastic.co/u/infofs)\
**Post date:** [March 27, 2023, 8:02am UTC](https://discuss.elastic.co/t/supplement-vlan-id-to-dns-data/328453/3 "2023-03-27T08:02:23Z")

</div>

Thank you, Andrew. I followed your advice and opened [Provide vlan.id in decoded protocols · Issue #34932 · elastic/beats · GitHub](https://github.com/elastic/beats/issues/34932).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 24, 2023, 10:02am UTC](https://discuss.elastic.co/t/supplement-vlan-id-to-dns-data/328453/4 "2023-04-24T10:02:34Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
