# Windows DNS parsing

**URL:** <https://discuss.elastic.co/t/windows-dns-parsing/205437>\
**Category:** Logstash\
**Created:** [October 28, 2019, 10:16am UTC](https://discuss.elastic.co/t/windows-dns-parsing/205437 "2019-10-28T10:16:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Jan\_Kaspar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jan_kaspar/32/44443_2.png) [@Jan\_Kaspar](https://discuss.elastic.co/u/Jan_Kaspar)\
**Post date:** [October 28, 2019, 10:16am UTC](https://discuss.elastic.co/t/windows-dns-parsing/205437/1 "2019-10-28T10:16:33Z")

</div>

Hi All,

I would like to ask you for help. I am trying to parse Microsoft DNS debug logs but I stucked.  
My testing environment is running on ELK version 7.2. Beats are also running on 7.2 version.

Problem is I am getting \_grokparsefailure also in case that grok debuger show me it should work.

My config files

**input.conf:**

input {  
beats {  
port =\> 5051  
type =\> "dns"  
}  
}

**dns.conf:**  
filter {  
if [type] == "dns" {  
if [message] =~ /^$/ {  
drop { }  
} else {  
grok {  
patterns\_dir =\> ["/etc/logstash/conf.d/patterns"]  
match =\> { "Message" =\> "%{MS\_DNS\_DATE:date}\s+%{TIME:time}\s+%{DATA:thread\_id}\s+%{WORD:dns\_type}\s+%{BASE16NUM:packet\_id}\s+%{WORD:dns\_protocol}\s+%{WORD:dns\_direction}\s+%{IP:dns\_ip}\s+%{BASE16NUM:xid}\s+%{DATA:response}\s+%{WORD:dns\_query\_type}\s+[%{BASE16NUM:hex\_flags}\s+%{WORD:flags}\s+%{WORD:rcode\_name}]\s+%{WORD:query\_type\_name}\s+%{GREEDYDATA:dns\_domain}"}  
match =\> { "Message" =\> "%{MS\_DNS\_DATE:date}\s+%{TIME:time}\s+%{DATA:thread\_id}\s+%{WORD:dns\_type}\s+%{BASE16NUM:packet\_id}\s+%{WORD:dns\_protocol}\s+%{WORD:dns\_direction}\s+%{IP:dns\_ip}\s+%{BASE16NUM:xid}\s+%{DATA:response}\s+%{WORD:dns\_query\_type}\s+[%{BASE16NUM:hex\_flags}\s+%{WORD:flags}\s+%{WORD:recursion}\s+%{WORD:rcode\_name}]\s+%{WORD:query\_type\_name}\s+%{GREEDYDATA:dns\_domain}"}  
match =\> { "Message" =\> "%{MS\_DNS\_DATE:date}\s+%{TIME:time}\s+%{DATA:thread\_id}\s+%{WORD:dns\_type}\s+%{BASE16NUM:packet\_id}\s+%{WORD:dns\_protocol}\s+%{WORD:dns\_direction}\s+%{IP:dns\_ip}\s+%{BASE16NUM:xid}\s+%{DATA:response}\s+%{WORD:dns\_query\_type}\s+[%{BASE16NUM:hex\_flags}\s+%{WORD:recursion}\s+%{WORD:rcode\_name}]\s+%{WORD:query\_type\_name}\s+%{GREEDYDATA:dns\_domain}"}  
match =\> { "Message" =\> "%{MS\_DNS\_DATE:date}\s+%{TIME:time}\s+%{DATA:thread\_id}\s+%{WORD:dns\_type}\s+%{BASE16NUM:packet\_id}\s+%{WORD:dns\_protocol}\s+%{WORD:dns\_direction}\s+%{IP:dns\_ip}\s+%{BASE16NUM:xid}\s+%{DATA:response}\s+%{WORD:dns\_query\_type}\s+[%{BASE16NUM:hex\_flags}\s+%{WORD:rcode\_name}]\s+%{WORD:query\_type\_name}\s+%{GREEDYDATA:dns\_domain}"}  
match =\> { "Message" =\> "%{MS\_DNS\_DATE:date}\s+%{TIME:time}\s+%{DATA:thread\_id}\s+%{WORD:dns\_type}\s+%{BASE16NUM:packet\_id}\s+%{WORD:dns\_protocol}\s+%{WORD:dns\_direction}\s+%{IP:dns\_ip}\s+%{BASE16NUM:xid}\s+%{WORD:dns\_query\_type}\s+[%{BASE16NUM:hex\_flags}\s+%{WORD:flags}\s+%{WORD:rcode\_name}]\s+%{WORD:query\_type\_name}\s+%{GREEDYDATA:dns\_domain}"}  
}  
}  
}  
}

**custom pattern:**  
MS\_DNS\_DATE %{MONTHDAY}. %{MONTHNUM}. %{YEAR}

**Sample log line:** (date is with spaces so i made custom patern)  
28. 10. 2019 10:52:48 0A38 PACKET 000000DE7BBC74B0 UDP Snd 192.168.5.201 98af Q [0000 NOERROR] SOA (4)mell(2)cz(0)

If i try to parse that sample in GROK DEBUGGER it works with pattern:

_%{MS\_DNS\_DATE:date}\s+%{TIME:time}\s+%{DATA:thread\_id}\s+%{WORD:dns\_type}\s+%{BASE16NUM:packet\_id}\s+%{WORD:dns\_protocol}\s+%{WORD:dns\_direction}\s+%{IP:dns\_ip}\s+%{BASE16NUM:xid}\s+%{DATA:response}\s+%{WORD:dns\_query\_type}\s+[%{BASE16NUM:hex\_flags}\s+%{WORD:rcode\_name}]\s+%{WORD:query\_type\_name}\s+%{GREEDYDATA:dns\_domain}_

Can someone help me with debugging?

Thanks.

Jan

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 28, 2019, 12:08pm UTC](https://discuss.elastic.co/t/windows-dns-parsing/205437/2 "2019-10-28T12:08:50Z")

</div>

Have you escaped the square brackets using \ ?

---

<div class="post-metadata">

**Author:** ![Jan\_Kaspar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jan_kaspar/32/44443_2.png) [@Jan\_Kaspar](https://discuss.elastic.co/u/Jan_Kaspar)\
**Post date:** [October 28, 2019, 1:06pm UTC](https://discuss.elastic.co/t/windows-dns-parsing/205437/3 "2019-10-28T13:06:16Z")

</div>

I found it, it was problem with case sensitivity.

Wrong: "Message" =\> "  
Right: "message"=\> "

Jan

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 25, 2019, 1:06pm UTC](https://discuss.elastic.co/t/windows-dns-parsing/205437/4 "2019-11-25T13:06:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
