# Filebeat DNS lookup failure after upgrading coreDNS

**URL:** <https://discuss.elastic.co/t/filebeat-dns-lookup-failure-after-upgrading-coredns/238621>\
**Category:** Beats\
**Created:** [June 25, 2020, 8:25am UTC](https://discuss.elastic.co/t/filebeat-dns-lookup-failure-after-upgrading-coredns/238621 "2020-06-25T08:25:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tech\_Techie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tech_techie/32/56636_2.png) [@Tech\_Techie](https://discuss.elastic.co/u/Tech_Techie)\
**Post date:** [June 25, 2020, 8:25am UTC](https://discuss.elastic.co/t/filebeat-dns-lookup-failure-after-upgrading-coredns/238621/1 "2020-06-25T08:25:47Z")

</div>

I was upgrading the EKS version to 1.15 and after I upgrade the coreDNS version to 1.6.6. I got an error log from the filebeat

```auto
2020-06-20T20:00:43.298Z	WARN	transport/tcp.go:53	DNS lookup failure "logstash-collection-headless.etl.svc.cluster.local": lookup logstash-collection-headless.etl.svc.cluster.local: no such host
2020-06-20T20:00:44.299Z	ERROR	pipeline/output.go:121	Failed to publish events: lookup logstash-collection-headless.etl.svc.cluster.local: no such host
2020-06-20T20:00:44.299Z	INFO	pipeline/output.go:95	Connecting to backoff(tcp://logstash-collection-headless.etl.svc.cluster.local:5044)
2020-06-20T20:00:44.340Z	INFO	pipeline/output.go:105	Connection to backoff(tcp://logstash-collection-headless.etl.svc.cluster.local:5044) established

```

What might be causing this error. Any other application can easily ping to the logstash application  
The configuration for filebeat is

```auto
path.data: /usr/local/httpd/logs/filebeat-data
filebeat.inputs:
- type: log
  paths:
    - /usr/local/httpd/logs/fragment.log*
  close_inactive: 1h
  close_renamed: false
  close_removed: false
  fields:
    log_type: fragment
  fields_under_root: true

logging.level: info
logging.to_files: true
logging.files:
  path: /var/log/filebeat
  name: filebeat
  keepfiles: 7
  permissions: 0644

output.logstash:
  hosts: ["${LOGSTASH_URL}"]
  ttl: 1s
  pipelining: 0

processors:
- drop_fields:
    fields: ["beat", "host", "input", "prospector"]

xpack.monitoring:
  enabled: true
  elasticsearch:
    hosts: ["${ELASTICSEARCH_URL}"]
    protocol: "http"

name: ${NODE_NAME}

```

Environment for filebeat

```auto
env:
          - name: "LOGSTASH_URL"
            value: "logstash-collection-headless.etl.svc.cluster.local:5044"

```

---

<div class="post-metadata">

**Author:** ![Tech\_Techie](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/tech_techie/32/56636_2.png) [@Tech\_Techie](https://discuss.elastic.co/u/Tech_Techie)\
**Post date:** [July 1, 2020, 8:42am UTC](https://discuss.elastic.co/t/filebeat-dns-lookup-failure-after-upgrading-coredns/238621/2 "2020-07-01T08:42:27Z")

</div>

No any reply??

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 29, 2020, 10:42am UTC](https://discuss.elastic.co/t/filebeat-dns-lookup-failure-after-upgrading-coredns/238621/3 "2020-07-29T10:42:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
