# Adding syslog ports to filebeats filter

**URL:** <https://discuss.elastic.co/t/adding-syslog-ports-to-filebeats-filter/198438>\
**Category:** Logstash\
**Created:** [September 6, 2019, 2:27pm UTC](https://discuss.elastic.co/t/adding-syslog-ports-to-filebeats-filter/198438 "2019-09-06T14:27:54Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![c0mputernick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/c0mputernick/32/53730_2.png) [@c0mputernick](https://discuss.elastic.co/u/c0mputernick)\
**Post date:** [September 6, 2019, 2:27pm UTC](https://discuss.elastic.co/t/adding-syslog-ports-to-filebeats-filter/198438/1 "2019-09-06T14:27:54Z")

</div>

Id like to get logstash accepting syslogs on the default 514 ports both tcp and udp.

Im trying to follow this guide for the filters :  
[https://www.elastic.co/guide/en/logstash/6.7/logstash-config-for-filebeat-modules.html#parsing-system](https://www.elastic.co/guide/en/logstash/6.7/logstash-config-for-filebeat-modules.html#parsing-system)

But im not sure if i can use this syslog filter for both filebeats and native syslog?

If i can use it for both, is there a way to list more than one port so it can listen for all of them?  
5044 and 514 tcp/udp?

Maybe just keep adding ports like this example?  
[https://www.elastic.co/guide/en/logstash/current/config-examples.html#\_processing\_syslog\_messages](https://www.elastic.co/guide/en/logstash/current/config-examples.html#_processing_syslog_messages)

Thanks for the help.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 6, 2019, 3:08pm UTC](https://discuss.elastic.co/t/adding-syslog-ports-to-filebeats-filter/198438/2 "2019-09-06T15:08:21Z")

</div>

> [@c0mputernick](#):
>
> is there a way to list more than one port so it can listen for all of them?

You can listen on multiple ports by adding additional inputs. Each input will only listen on one port.

---

<div class="post-metadata">

**Author:** ![c0mputernick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/c0mputernick/32/53730_2.png) [@c0mputernick](https://discuss.elastic.co/u/c0mputernick)\
**Post date:** [September 6, 2019, 3:20pm UTC](https://discuss.elastic.co/t/adding-syslog-ports-to-filebeats-filter/198438/3 "2019-09-06T15:20:11Z")

</div>

Should I be able to see it listening with netstat?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [September 6, 2019, 3:34pm UTC](https://discuss.elastic.co/t/adding-syslog-ports-to-filebeats-filter/198438/4 "2019-09-06T15:34:36Z")

</div>

Yes.

---

<div class="post-metadata">

**Author:** ![c0mputernick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/c0mputernick/32/53730_2.png) [@c0mputernick](https://discuss.elastic.co/u/c0mputernick)\
**Post date:** [September 6, 2019, 3:38pm UTC](https://discuss.elastic.co/t/adding-syslog-ports-to-filebeats-filter/198438/5 "2019-09-06T15:38:16Z")

</div>

Interesting.  
I added:

input {  
tcp {  
port =\> 514  
type =\> syslog  
}  
udp {  
port =\> 514  
type =\> syslog  
}  
}

And restarted logstash and then the server and i still do not see it listening on 514:

root@lxelk:~# netstat -tunlp  
Active Internet connections (only servers)  
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name  
tcp 0 0 0.0.0.0:80 0.0.0.0:\* LISTEN 1651/nginx: master  
tcp 0 0 127.0.0.53:53 0.0.0.0:\* LISTEN 1021/systemd-resolv  
tcp 0 0 0.0.0.0:22 0.0.0.0:\* LISTEN 1568/sshd  
tcp 0 0 127.0.0.1:5601 0.0.0.0:\* LISTEN 1148/node  
tcp6 0 0 ::1:9200 :::\* LISTEN 1295/java  
tcp6 0 0 127.0.0.1:9200 :::\* LISTEN 1295/java  
tcp6 0 0 :::80 :::\* LISTEN 1651/nginx: master  
tcp6 0 0 :::5044 :::\* LISTEN 1108/java  
tcp6 0 0 ::1:9300 :::\* LISTEN 1295/java  
tcp6 0 0 127.0.0.1:9300 :::\* LISTEN 1295/java  
tcp6 0 0 :::22 :::\* LISTEN 1568/sshd  
tcp6 0 0 127.0.0.1:9600 :::\* LISTEN 1108/java  
udp 0 0 127.0.0.53:53 0.0.0.0:\* 1021/systemd-resolv

Looks like only kibana on 5601.  
No firewall involved. ufw is disabled.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 4, 2019, 3:38pm UTC](https://discuss.elastic.co/t/adding-syslog-ports-to-filebeats-filter/198438/6 "2019-10-04T15:38:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
