# All syslogs appear to come from the same host

**URL:** <https://discuss.elastic.co/t/all-syslogs-appear-to-come-from-the-same-host/196119>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 21, 2019, 1:17pm UTC](https://discuss.elastic.co/t/all-syslogs-appear-to-come-from-the-same-host/196119 "2019-08-21T13:17:09Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmorris](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jmorris](https://discuss.elastic.co/u/jmorris)\
**Post date:** [August 21, 2019, 1:17pm UTC](https://discuss.elastic.co/t/all-syslogs-appear-to-come-from-the-same-host/196119/1 "2019-08-21T13:17:09Z")

</div>

I have several devices sending syslogs to my server, but in Kibana, all of them have the exact same host/agent name, so its impossible to visualize groups. For example, if I wanted to see all alerts from my core switch, there wouldn't be anything to differentiate its messages from an AP.

Is this intended behavior?

---

<div class="post-metadata">

**Author:** ![Justin\_Doles](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_doles/32/40730_2.png) [@Justin\_Doles](https://discuss.elastic.co/u/Justin_Doles)\
**Post date:** [August 21, 2019, 2:37pm UTC](https://discuss.elastic.co/t/all-syslogs-appear-to-come-from-the-same-host/196119/2 "2019-08-21T14:37:17Z")

</div>

I've recently noticed this as well. It seems like this is intentional, but I'm not sure it makes any sense. There should be a way to differentiate sources.

Unless there's something we're missing, I'll be going back to logstash to solve this.

---

<div class="post-metadata">

**Author:** ![jmorris](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jmorris](https://discuss.elastic.co/u/jmorris)\
**Post date:** [August 21, 2019, 7:38pm UTC](https://discuss.elastic.co/t/all-syslogs-appear-to-come-from-the-same-host/196119/3 "2019-08-21T19:38:17Z")

</div>

I'm not sure I'm advanced enough to do this. Is there  
documentation on how to replace filebeat with logstash? Or is  
logstash just another link in the chain?

---

<div class="post-metadata">

**Author:** ![Justin\_Doles](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_doles/32/40730_2.png) [@Justin\_Doles](https://discuss.elastic.co/u/Justin_Doles)\
**Post date:** [August 22, 2019, 1:46pm UTC](https://discuss.elastic.co/t/all-syslogs-appear-to-come-from-the-same-host/196119/4 "2019-08-22T13:46:26Z")

</div>

I'm not sure there's something that specific. Logstash supports syslog out of the box. [https://www.elastic.co/guide/en/logstash/current/plugins-inputs-syslog.html](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-syslog.html)

You may need to make some changes in your environment depending on what you're logging. Cisco, for example, doesn't use RFC3164 for syslog. But if you search around you'll find some config samples for Cisco. If you get hung up, you can always ask in the Logstash forum. It is easy to get lost in the config.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2019, 1:46pm UTC](https://discuss.elastic.co/t/all-syslogs-appear-to-come-from-the-same-host/196119/5 "2019-09-19T13:46:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
