# Dns timeout error

**URL:** <https://discuss.elastic.co/t/dns-timeout-error/81293>\
**Category:** Logstash\
**Created:** [April 5, 2017, 10:19am UTC](https://discuss.elastic.co/t/dns-timeout-error/81293 "2017-04-05T10:19:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![vaishnavi](https://avatars.discourse-cdn.com/v4/letter/v/f19dbf/32.png) [@vaishnavi](https://discuss.elastic.co/u/vaishnavi)\
**Post date:** [April 5, 2017, 10:19am UTC](https://discuss.elastic.co/t/dns-timeout-error/81293/1 "2017-04-05T10:19:28Z")

</div>

Hi,  
I am using logstash to process large files which involves many IPs and I need to convert IP to hostname in logstash using dns filter without any time delay  
I am already using DNS filter which convert IP to hostname but for unresolved IPS it take 5 to 15 seconds and displays time out error.  
For nearly 1000 IPs it takes a minimum of 1 hour to push data to elasticsearch  
I need to push data in faster manner and how can I achieve this?

currently I am using centos 7, logstash 5.2 , elasticsearch 5.0.1

My conf file is

> dns {  
> reverse =\> "source\_ip\_dns"  
> timeout =\>0.1   
> hit\_cache\_size =\> 4096  
> hit\_cache\_ttl =\> 900  
> failed\_cache\_size =\> 512  
> failed\_cache\_ttl =\> 900  
> action =\> "replace"  
> }

Any help would be appreciated

---

<div class="post-metadata">

**Author:** ![danlobo](https://avatars.discourse-cdn.com/v4/letter/d/e8c25b/32.png) [@danlobo](https://discuss.elastic.co/u/danlobo)\
**Post date:** [April 11, 2017, 2:20pm UTC](https://discuss.elastic.co/t/dns-timeout-error/81293/2 "2017-04-11T14:20:47Z")

</div>

I'm having the same issue.

My setup involves a Redis broker, and when the DNS plugin is enabled the buffer keeps increasing for about an hour. This doesn't happen when the filter is disabled.

Changed some parameters, like hit cache size and failed cache size; also installed a local dns cache (dnsmasq), but no improvements.

[Edit]

GET /\_node/stats/pipeline

```
{
    version: "5.2.2",
    <...>
    pipeline: {
        events: {
            duration_in_millis: 460233,
            in: 11904,
            filtered: 1664,
            out: 1664
        },
        plugins: {
        inputs: [],
        filters: [
            <...>
            {
                id: "<...>",
                events: {
                    duration_in_millis: 5820837,
                    in: 1386,
                    out: 1306
                },
                name: "dns"
            },
            <...>
        }]
    }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2017, 2:34pm UTC](https://discuss.elastic.co/t/dns-timeout-error/81293/3 "2017-05-09T14:34:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
