quoting OP:
Hi all,
For the benefit of everybody here, I got the hostname resolution to work. Here are the steps as follows:-
1.) Install the logstash-filter-dns plugin as follows:-
/usr/share/logstash/bin/logstash-plugin install logstash-filter-dns
2.) Edit the /etc/logstash/conf.d/logstash.conf file as follows:-
filter {
dns {
reverse => [ "src_ip" ]
action => "replace"
}
}
filter {
dns {
reverse => [ "dest_ip" ]
action => "replace"
}
}
Add this after (or maybe before) the current filter section and save the file with the new filters included.
3.) Restart logstash:-
service logstash restart
Give it a while and the FQDN's appear in both EveBox and Kibana.
Thank you.