Skip to content
System

System Event ID 1014: DNS resolution timeout

Name resolution for the name timed out after none of the configured DNS servers respondedSystem event 1014 (DNS Client) is logged when a name lookup timed out because none of the configured DNS servers answered. Mostly network noise.
1014
Event ID
1014
Channel
System
Provider
Microsoft-Windows-DNS-Client
Log file
System.evtx
Category
Network
Default logging
Logged by default

What event 1014 means

Event 1014 is a warning from the DNS Client service: a query for QueryName got no answer from any configured DNS server before the timeout. It says nothing about whether the name exists — only that the servers did not respond in time.

In practice it is dominated by network trouble: VPN transitions, Wi-Fi roaming, captive portals, a DNS server down, or queries for internal names (wpad, isatap, domain SRV records) made while the host is off the corporate network. Its forensic value is modest but real: QueryName shows names the host tried to resolve at a given time, even when no DNS Client Operational logging (3006/3008) is enabled.

A recurring timeout for an unfamiliar domain can reveal software — or malware — that keeps trying to reach a server that no longer answers.

When it is logged

Audit policy / configuration

Always logged to the System log (Warning level).

Only failed lookups appear here. For every query, enable the DNS Client Operational log (events 3006, 3008, 3020) or use Sysmon event 22.

Key fields

FieldWhat it tells you
QueryNameThe name that could not be resolved.
AddressLengthLength in bytes of the DNS server address data attached to the event.

Common benign sources

  • Laptops off the corporate network trying to resolve internal names and WPAD.
  • VPN connect or disconnect, sleep/resume and network changes.
  • Misconfigured or overloaded DNS servers.

What attackers do that produces it

  • Implants beaconing to a command-and-control domain whose DNS infrastructure has been taken down or blocked, producing repeated timeouts for the same unusual name.

Investigation tips

  • Aggregate QueryName values and discard internal and well-known vendor domains first.
  • For a suspicious name, find the requesting process with Sysmon 22 or DNS Client 3008 if available, or with network telemetry.
  • Check threat intelligence for the domain and whether other hosts log the same name.

Sigma rules for this event

No bundled SigmaHQ rule targets this event ID specifically. Rules on related events may still cover the activity.

Run these rules on your logs

Drop a .evtx file into the viewer: all 2,395 bundled SigmaHQ rules run locally in your browser. Nothing is uploaded.

Sources and further reading