# Troubling with add\_field in filter. Please advice

**URL:** <https://discuss.elastic.co/t/troubling-with-add-field-in-filter-please-advice/40848>\
**Category:** Logstash\
**Created:** [February 3, 2016, 9:28am UTC](https://discuss.elastic.co/t/troubling-with-add-field-in-filter-please-advice/40848 "2016-02-03T09:28:39Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![alfsolli](https://avatars.discourse-cdn.com/v4/letter/a/8c91f0/32.png) [@alfsolli](https://discuss.elastic.co/u/alfsolli)\
**Post date:** [February 3, 2016, 9:28am UTC](https://discuss.elastic.co/t/troubling-with-add-field-in-filter-please-advice/40848/1 "2016-02-03T09:28:39Z")

</div>

Hi.

Fresh off the boat ELK user here.

Can someone point out what I'm doing wrong here? I'm trying to translate a field (IP address) into FQDN with logstash.  
The data source is netflow, and I'm trying to get the IP address from the ipv4\_dst\_addr field into a separate field, translated.

My logstash.conf :

input {

stdin { } # debug mode

udp {  
type =\> netflow  
port =\> 9995

# metadata =\> true \<- This setting gave me an error, so it's commented out. is it vital?

```
  codec => netflow {
    versions => [5,9,10]
  }
}

```

#file {

# type =\> "apache"

# path =\> ["/var/log/apache2/access\_log", "/var/log/apache2/error\_log"]

# start\_position =\> "beginning"

# }

}

filter {

if [type] == "netflow" {

```
    mutate {
    add_field => { "hostname" => "%{ipv4_dst_addr}" }
        }
  dns {
  action => "replace"
  reverse => "hostname"
  add_tag => ["dns_lookup"]
}
}

```

if [type] == "apache" {  
grok {  
match =\> { "message" =\> "%{COMMONAPACHELOG}" }  
}  
geoip {  
source =\> "clientip"  
target =\> "geoip"  
database =\> "/etc/logstash/GeoLiteCity.dat"  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][longitude]}" ]  
add\_field =\> ["[geoip][coordinates]", "%{[geoip][latitude]}" ]  
}  
mutate {  
convert =\> ["[geoip][coordinates]", "float"]  
}  
}

}

output {

stdout {  
codec =\> rubydebug { metadata =\> true }  
}

#elasticsearch {

# protocol =\> "http"

# hosts =\> ["192.168.10.30"]

# } \<- Disabled until it works

}

I receiev output from a Cisco Meraki Z1 netflow which looks like this (logstash stdout ) :

No matching template for flow id 5206 {:level=\>:warn}  
No matching template for flow id 5206 {:level=\>:warn}  
No matching template for flow id 5206 {:level=\>:warn}  
No matching template for flow id 5206 {:level=\>:warn}  
{  
"@timestamp" =\> "2016-02-03T09:24:40.000Z",  
"netflow" =\> {  
"version" =\> 9,  
"flow\_seq\_num" =\> 721581,  
"flowset\_id" =\> 5206,  
"ipv4\_src\_addr" =\> "192.168.10.7",  
"ipv4\_dst\_addr" =\> "255.255.255.255", \<- This IP address, should be moved to the "hostname" field, and translated.  
"l4\_src\_port" =\> 35432,  
"l4\_dst\_port" =\> 1900,  
"in\_bytes" =\> 0,  
"out\_bytes" =\> 0,  
"in\_pkts" =\> 0,  
"out\_pkts" =\> 0,  
"protocol" =\> 17  
},  
"@version" =\> "1",  
"type" =\> "netflow",  
"host" =\> "192.168.10.254", \<- this is my Meraki, no need to translate that.  
"hostname" =\> "%{ipv4\_dst\_addr}" \<- This is what I get instead.  
}

Any pointers is appreciated. 🙂

Kind regards  
Alf Solli

---

<div class="post-metadata">

**Author:** ![alfsolli](https://avatars.discourse-cdn.com/v4/letter/a/8c91f0/32.png) [@alfsolli](https://discuss.elastic.co/u/alfsolli)\
**Post date:** [February 3, 2016, 9:36am UTC](https://discuss.elastic.co/t/troubling-with-add-field-in-filter-please-advice/40848/2 "2016-02-03T09:36:29Z")

</div>

I forgot. Using logstash-2.1.1-1.noarch, from rpm.

Sorry about the weird formatting. How do I enclose code and config examples properly?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:13am UTC](https://discuss.elastic.co/t/troubling-with-add-field-in-filter-please-advice/40848/3 "2017-07-06T05:13:16Z")

</div>


