# Logstash stops processing syslog messages when DNS server not available

**URL:** <https://discuss.elastic.co/t/logstash-stops-processing-syslog-messages-when-dns-server-not-available/339334>\
**Category:** Logstash\
**Created:** [July 26, 2023, 5:07pm UTC](https://discuss.elastic.co/t/logstash-stops-processing-syslog-messages-when-dns-server-not-available/339334 "2023-07-26T17:07:09Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![RJC](https://avatars.discourse-cdn.com/v4/letter/r/f14d63/32.png) [@RJC](https://discuss.elastic.co/u/RJC)\
**Post date:** [July 26, 2023, 5:07pm UTC](https://discuss.elastic.co/t/logstash-stops-processing-syslog-messages-when-dns-server-not-available/339334/1 "2023-07-26T17:07:09Z")

</div>

Running Logstash 8.5.2 on RHEL.

I implemented DNS filter plugin to resolve IP addresses to hostnames for all syslog nodes reporting to this logstash server. I am using our local DNS server.

It all worked perfectly until DNS server went offline. When that happened logstash stopped processing all messages from all nodes. Logstash did not crash and its status was shown as active (running).

The moment DNS server came back of line, logstash started processing the messages again.

This means that every time DNS server becomes unavailable we will lose syslog messages.

Is there any solution to this problem?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 23, 2023, 5:07pm UTC](https://discuss.elastic.co/t/logstash-stops-processing-syslog-messages-when-dns-server-not-available/339334/2 "2023-08-23T17:07:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
