# Reverse DNS processor multiple nameservers problem

**URL:** <https://discuss.elastic.co/t/reverse-dns-processor-multiple-nameservers-problem/306704>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 8, 2022, 1:56pm UTC](https://discuss.elastic.co/t/reverse-dns-processor-multiple-nameservers-problem/306704 "2022-06-08T13:56:48Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![unknotted-evacuee](https://avatars.discourse-cdn.com/v4/letter/u/cc9497/32.png) [@unknotted-evacuee](https://discuss.elastic.co/u/unknotted-evacuee)\
**Post date:** [June 8, 2022, 1:56pm UTC](https://discuss.elastic.co/t/reverse-dns-processor-multiple-nameservers-problem/306704/1 "2022-06-08T13:56:48Z")

</div>

Hey  
filebeat version 8.0.1

I'm suspecting a problem with using multiple namespaces for the DNS processor.

My config looks like this (with dummy ip addresses, and I was testing with a low ttl in failure\_cache):

```auto
      - dns:
          type: reverse
          fields:
            log.source.ip: log.source.hostname
          failure_cache:
            ttl: 2s
          nameservers: ['1.2.3.4', '5.6.7.8']
          timeout: 200ms
          tag_on_failure: [_dns_reverse_lookup_failed]

```

My log shows that the config is parsed:

```auto
Jun 08 15:29:06 xxx filebeat[2323040]: {"log.level":"debug","@timestamp":"2022-06-08T15:29:06.680+0200","log.logger":"processor.dns","log.origin":{"file.name":"dns/dns.go","file.line":67},"message"
:"DNS processor config: {CacheConfig:{SuccessCache:{TTL:0s MinTTL:1m0s InitialCapacity:1000 MaxCapacity:10000} FailureCache:{TTL:2s MinTTL:1m0s InitialCapacity:1000 MaxCapacity:10000}} Nameservers:[1.2.3.4 5.6.7.8] Timeout:200ms Type:reverse Action:append TagOnFailure:[_dns_reverse_lookup_failed] Fields:{\"log\":{\"source\":{\"ip\":\"log.source.hostname\"}}} Transport:udp reverseFlat:map[log.source.ip:log.source.hostname]}","s
ervice.name":"filebeat","instance_id":1,"ecs.version":"1.6.0"}

```

Then the log shows multiple lines like this:

```auto
Jun 08 15:50:20 xxxx filebeat[2323040]: {"log.level":"debug","@timestamp":"2022-06-08T15:50:20.275+0200","log.logger":"processor.dns","log.origin":{"file.name":"dns/dns.go","file.line":85},"message"
:"DNS processor failed: reverse lookup of log.source.ip value '5.66.77.88' failed: dns: nameserver 1.2.3.4:53 returned SERVFAIL","service.name":"filebeat","instance_id":1,"ecs.version":"1.6.0"}

```

So it is only testing the first of the two nameservers from the config file.

Any ideas here? According to the documentation it should go through the list of nameservers if the first one fails.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2022, 3:57pm UTC](https://discuss.elastic.co/t/reverse-dns-processor-multiple-nameservers-problem/306704/2 "2022-07-06T15:57:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
