# Adding parameters from grok to syslog output

**URL:** <https://discuss.elastic.co/t/adding-parameters-from-grok-to-syslog-output/149269>\
**Category:** Logstash\
**Created:** [September 20, 2018, 10:23am UTC](https://discuss.elastic.co/t/adding-parameters-from-grok-to-syslog-output/149269 "2018-09-20T10:23:07Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![karasmeitar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/karasmeitar/32/35703_2.png) [@karasmeitar](https://discuss.elastic.co/u/karasmeitar)\
**Post date:** [September 20, 2018, 10:23am UTC](https://discuss.elastic.co/t/adding-parameters-from-grok-to-syslog-output/149269/1 "2018-09-20T10:23:07Z")

</div>

Hi All,  
I'm trying to add my syslog ip server from in my grok filter and consume it in my logstash syslog output.  
In the filter section i'm adding the following:  
mutate {  
add\_field =\> {  
"IP" =\> "10.10.10.1"  
"port" =\> 516  
}  
}

in the output i'm adding:  
syslog {  
host =\> "%{IP}"  
port =\> "%{port}"  
}

I have two problems with this configuration:

1. with the type of the port.. i'm getting error that it should be a number
2. with the IP, when i changed the port manually to 512 i'm still not getting the logs.

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 18, 2018, 10:23am UTC](https://discuss.elastic.co/t/adding-parameters-from-grok-to-syslog-output/149269/2 "2018-10-18T10:23:08Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
