I am using the logstash UDP input to receive my firewall syslog messages, this seems to work fine.
However, I just enabled the reverse dns lookup filter on the ip's, but now I keep wondering what happens when the UDP packet queue fills up. This is currently set to the default of 2000.
My main question is, if the queue does fill up and packets are being dropped, is there any way to know if this is happening? I suspect it would be logged to logstash-plain.log? But I cannot seem to find anything about it online.
Thanks in advance,