I have a server where I installed DNS RPZ and have windows DNS Server. I am getting logs from logstash to graylog which is installed on DNS RPZ Server; while at the same time I installed packetbeat on the windows server and then sending logs to logstash to DNS RPZ and then to graylog from there.
192.168.5.111 → Windows DNS Server with Packetbeat
192.168.5.112 → BIND DNS RPZ with graylog/logstash
Here is the situation which I am unable to resolve. The logs for now are coming in “All Messages”
By chance are you using the Beat Input for 192.168.5.111 → Windows DNS Server with Packetbeat and a different Input for 192.168.5.112 → BIND DNS RPZ with graylog/logstash? The reason I ask this is to make sure you getting the right fields needed for you Data table ( i.e. Widget).
To be honest some more information would help specially for what your doing with the data table.
I am using 3.3.16 and have already created the dashboards or aggregations however as I said I am unable to plot those fields in a single aggregation. Here e.g.
Have to tried other configurations? Meaning changing the order of the fields but keeping clientipaddr there clientipaddr —> packetbeat_client_ip → odomain
clientipaddr is being search and for/each clientipaddr there is a filed called odomain which I seen was listed above, then you adding packetbeat_client_ip after each odomain. Perhaps each field odomain does not have a packetbeat_client_ip fileld/s. Just a guess.
My apologies, I no long have version GL 3,3 and its been awhile so I’m going off memory on what might have happened.
I did a test in my lab and I can not use a Beat INPUT with GELF TCP/TLS INPUT, results are NULL.
I’m sorry but it might not, I have version 4.2.6 and I’m unable to get data from both types of INPUTS.
What I get is you have two fields /w IP address from two different sources/types coming in and want to match them with a domain. Depending on how bad you want this widget to work, you can use a extractor /pipelines and create unique fields that would be able get the information you need or create a widget for each. On the other hand, perhaps posting here may help.