# Odd DNS filter behaviour prevents event processing

**URL:** <https://discuss.elastic.co/t/odd-dns-filter-behaviour-prevents-event-processing/115279>\
**Category:** Logstash\
**Created:** [January 12, 2018, 11:13am UTC](https://discuss.elastic.co/t/odd-dns-filter-behaviour-prevents-event-processing/115279 "2018-01-12T11:13:03Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![chrbraun](https://avatars.discourse-cdn.com/v4/letter/c/df705f/32.png) [@chrbraun](https://discuss.elastic.co/u/chrbraun)\
**Post date:** [January 12, 2018, 11:13am UTC](https://discuss.elastic.co/t/odd-dns-filter-behaviour-prevents-event-processing/115279/1 "2018-01-12T11:13:03Z")

</div>

I recently upgraded my elastic Stack to 6.x.Since 2 days I noticed a weird behaviour which results in a significant amount of events being dropped.

I have a DNS filter which does a reverse lookup on all internal IPs which makes it easier to search for specific machines. After the upgrade logstash runs for ~15 minutes before the logstash.log gets flooded with DNS request timeouts. I added a cache option which improved the situation quiet a bit but after two hours the same problems started to arise. My question is: Is anybody experiencing something similiar? Is there something I am missing?

1. After the Upgrade

![grafik](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f56783664be1c986545623eff6bed57f7661d5c7.png)

1. After setting a cache:

 ![grafik](https://us1.discourse-cdn.com/elastic/original/3X/c/1/c1eb23a27132bda4b0d217ff165cf9a6f3abed96.png)

This is the filter in question:

```
filter {
mutate {
    rename => { "dstport" => "dst_port" }
    rename => { "srcport" => "src_port" }
}

if [src_ip] {
    if [src_ip] =~ /10\..*/ {
        mutate {
            add_field => { "src_ip_resolve" => "%{src_ip}"}
        }
        dns {
            action => "replace"
            reverse => ["src_ip_resolve"]
            nameserver => ["10.0.1.21", "10.0.1.22"]
            hit_cache_size => 8000
            hit_cache_ttl => 900
            failed_cache_size => 1000
            failed_cache_ttl => 300
        }
    } else {
        geoip {
            source => "src_ip"
            target => "src_ip_geo"
            fields => ["city_name","country_name"]
        }
    }
}

if [dst_ip] {
    if [dst_ip] =~ /10\..*/ {
        mutate {
            add_field => { "dst_ip_resolve" => "%{dst_ip}"}
        }
        dns {
            action => "replace"
            reverse => ["dst_ip_resolve"]
            nameserver => ["10.0.1.21", "10.0.1.22"]
            hit_cache_size => 8000
            hit_cache_ttl => 900
            failed_cache_size => 1000
            failed_cache_ttl => 300
        }
    } else {
         geoip {
            source => "dst_ip"
            target => "dst_ip_geo"
            fields => ["city_name","country_name"]
        }
    }
}
```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2018, 11:13am UTC](https://discuss.elastic.co/t/odd-dns-filter-behaviour-prevents-event-processing/115279/2 "2018-02-09T11:13:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
