System Event ID 1014: DNS resolution timeout
- Event ID
- 1014
- Channel
- System
- Provider
- Microsoft-Windows-DNS-Client
- Log file
- System.evtx
- Category
- Network
- Default logging
- Logged by default
What event 1014 means
Event 1014 is a warning from the DNS Client service: a query for QueryName got no answer from any configured DNS server before the timeout. It says nothing about whether the name exists — only that the servers did not respond in time.
In practice it is dominated by network trouble: VPN transitions, Wi-Fi roaming, captive portals, a DNS server down, or queries for internal names (wpad, isatap, domain SRV records) made while the host is off the corporate network. Its forensic value is modest but real: QueryName shows names the host tried to resolve at a given time, even when no DNS Client Operational logging (3006/3008) is enabled.
A recurring timeout for an unfamiliar domain can reveal software — or malware — that keeps trying to reach a server that no longer answers.
When it is logged
Always logged to the System log (Warning level).
Only failed lookups appear here. For every query, enable the DNS Client Operational log (events 3006, 3008, 3020) or use Sysmon event 22.
Key fields
| Field | What it tells you |
|---|---|
| QueryName | The name that could not be resolved. |
| AddressLength | Length in bytes of the DNS server address data attached to the event. |
Common benign sources
- Laptops off the corporate network trying to resolve internal names and WPAD.
- VPN connect or disconnect, sleep/resume and network changes.
- Misconfigured or overloaded DNS servers.
What attackers do that produces it
- Implants beaconing to a command-and-control domain whose DNS infrastructure has been taken down or blocked, producing repeated timeouts for the same unusual name.
Investigation tips
- Aggregate
QueryNamevalues and discard internal and well-known vendor domains first. - For a suspicious name, find the requesting process with Sysmon 22 or DNS Client 3008 if available, or with network telemetry.
- Check threat intelligence for the domain and whether other hosts log the same name.
Sigma rules for this event
No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.
Run these rules on your logs
Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.