# DNS filter - unfrequent but regular error

**URL:** <https://discuss.elastic.co/t/dns-filter-unfrequent-but-regular-error/372975>\
**Category:** Logstash\
**Created:** [January 9, 2025, 7:31am UTC](https://discuss.elastic.co/t/dns-filter-unfrequent-but-regular-error/372975 "2025-01-09T07:31:33Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Po-temkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/po-temkin/32/138703_2.png) [@Po-temkin](https://discuss.elastic.co/u/Po-temkin)\
**Post date:** [January 9, 2025, 7:31am UTC](https://discuss.elastic.co/t/dns-filter-unfrequent-but-regular-error/372975/1 "2025-01-09T07:31:33Z")

</div>

Hello to everyone!  
Not long ago I started to use Logstash to collect syslog from various devices in our infrastructure.

To solve this problem, I created some amount of pipelines (now about 40) that help me route syslog to different files.  
Below you can see the example of pipeline configuration:

```auto
input {
    udp {
        port => 1140
    }
}

filter {
    dns {
        action => "replace"
        hit_cache_size => 500000
		max_retries => 10
        reverse => ["[host]" ]
    }
}

output {
    file {
        codec => line { format => "%{message}" }
        path => "E:/logstash/ans/ans_file_syslog/%{[host]}/%{+YYYY-MM-dd-HH}.log"
    }
}

```

Due to this configuration, I expected to see two behaviors:

1. If everything is OK with DNS, Logstash creates a folder with a DNS name of a particular network device
2. If something is wrong with the DNS lookup, I will see a folder with an IP address of this network device

To be sure that everything OK, I create a report that tells me about the second unwanted behavior. And the problem is that I observe this behavior every day, with different hosts and without any time correlation.

And the weirdest thing for me is that we have about ~30kk log messages per day, and only a couple of messages from different hosts correspond to described behavior.

So, is something wrong with my configuration?

P.S:  
Before we moved to Logstash, I didn't observe such behavior.

---

<div class="post-metadata">

**Author:** ![Po-temkin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/po-temkin/32/138703_2.png) [@Po-temkin](https://discuss.elastic.co/u/Po-temkin)\
**Post date:** [January 24, 2025, 1:47pm UTC](https://discuss.elastic.co/t/dns-filter-unfrequent-but-regular-error/372975/2 "2025-01-24T13:47:46Z")

</div>

I have to admit that the root cause is related to our infrastructure.  
We decided to add "timeout =\> 2" and the problem has gone.
