Yep here is the the message just changes the IP for Googles:
1516195367.174058 CNDYE23uGhnLzFS9J8 8.8.8.8 23872 8.8.8.8 53 udp 54914 - r4.res.office365.com - - - - 0 NOERROR T F F F 0 r4.res.office365.com.edgekey.net 300.000000 F
Since there is no information about the field name in your message whatsoever, it’s not possible to completely automatically extract that information into message fields.
But you could create a matching grok pattern if the structure of the message doesn’t change:
Think I am making progress but getting errors in server.log now for any new field:
" error=<{“type”:“mapper_parsing_exception”,“reason”:“failed to parse”,“caused_by”:{“type”:“illegal_argument_exception”,“reason”:“Can’t parse [index] value [not_analyzed] for field [id_orig_h], expected [true] or [false]”}}>"