# Logstash stop parsing IIS logs on Windows

**URL:** <https://discuss.elastic.co/t/logstash-stop-parsing-iis-logs-on-windows/80831>\
**Category:** Logstash\
**Created:** [March 31, 2017, 2:52pm UTC](https://discuss.elastic.co/t/logstash-stop-parsing-iis-logs-on-windows/80831 "2017-03-31T14:52:30Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![pad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pad/32/16861_2.png) [@pad](https://discuss.elastic.co/u/pad)\
**Post date:** [March 31, 2017, 2:52pm UTC](https://discuss.elastic.co/t/logstash-stop-parsing-iis-logs-on-windows/80831/1 "2017-03-31T14:52:30Z")

</div>

Hi,

I'm using Logstash (2.3.4) on Windows to parse IIS logs (IIS 8.5) on two different server, one on Azure and one on our datacenter.

With the same configuration and the same version of Logstash, the one on our datacenter works correctly but the one on Azure stop reading file once in a while. I have to restart it and the data aren't correctly read.

Is it possible to add some logs on Logstash to see what's happening on the server ?

Thanks for your answers.

---

<div class="post-metadata">

**Author:** ![pad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pad/32/16861_2.png) [@pad](https://discuss.elastic.co/u/pad)\
**Post date:** [March 31, 2017, 3:45pm UTC](https://discuss.elastic.co/t/logstash-stop-parsing-iis-logs-on-windows/80831/2 "2017-03-31T15:45:56Z")

</div>

Hi again,

I found how to add logs and I've got my error:  
`{:timestamp=>"2017-03-31T10:13:17.266000-0500", :message=>"DNS: timeout on resolving address.", :field=>"clientHostname", :value=>"xxx.xxx.xxx.xxx", :level=>:error}`

In the conf (the one you can find on the web), I've got this:

```
## Create a new field for the reverse DNS lookup below
#
add_field => { "clientHostname" => "%{clientIP}" }

## Do a reverse lookup on the client IP to get their hostname.
#
dns {
    ## Now that we've copied the clientIP into a new field we can
    # simply replace it here using a reverse lookup
    #
    action => "replace"
    reverse => ["clientHostname"]
}

```

When it can't do the reverse lookup, it seems to stop read the files. Can we tell it to stop the reverse lookup and keep analyse the rest of the line ?

Thanks.

---

<div class="post-metadata">

**Author:** ![jsvd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jsvd/32/6203_2.png) [@jsvd](https://discuss.elastic.co/u/jsvd)\
**Post date:** [March 31, 2017, 4:57pm UTC](https://discuss.elastic.co/t/logstash-stop-parsing-iis-logs-on-windows/80831/3 "2017-03-31T16:57:03Z")

</div>

Be careful when using the DNS filter since it does a network call for each event, and if the resolve takes time or the dns server doesn't respond, it can clog the pipeline.

This filter has several settings you can tune: it has a [timeout](https://www.elastic.co/guide/en/logstash/current/plugins-filters-dns.html#plugins-filters-dns-timeout) options, and it can also have a cache of configurable size to avoid dns requests for repeated ips/hosts.

---

<div class="post-metadata">

**Author:** ![pad](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pad/32/16861_2.png) [@pad](https://discuss.elastic.co/u/pad)\
**Post date:** [April 3, 2017, 8:49am UTC](https://discuss.elastic.co/t/logstash-stop-parsing-iis-logs-on-windows/80831/4 "2017-04-03T08:49:45Z")

</div>

Thanks, I will be careful with that option. For now, I deactivate this part to avoid any time out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 1, 2017, 8:49am UTC](https://discuss.elastic.co/t/logstash-stop-parsing-iis-logs-on-windows/80831/5 "2017-05-01T08:49:51Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
