# All syslogs have same severity

**URL:** <https://discuss.elastic.co/t/all-syslogs-have-same-severity/196390>\
**Category:** Logstash\
**Created:** [August 22, 2019, 6:53pm UTC](https://discuss.elastic.co/t/all-syslogs-have-same-severity/196390 "2019-08-22T18:53:56Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![jmorris](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jmorris](https://discuss.elastic.co/u/jmorris)\
**Post date:** [August 22, 2019, 6:53pm UTC](https://discuss.elastic.co/t/all-syslogs-have-same-severity/196390/1 "2019-08-22T18:53:56Z")

</div>

I'm still very new to elastic stack and I ditched filebeat because it made all of my syslogs look like they were coming from the same host. I have my syslogs coming into logstash now and for the most part its working, however, the syslog\_severity and syslog\_severity code always show up as 'notice' and '5' respectively, regardless of the data sent.

I tested with Kiwi, by sending 500 randomized messages, and all 500 of them came over as 'notice' and '5'.

Here's my filter in my config file:

> filter {  
> if [type] == "syslog" {  
> grok {  
> match =\> { "message" =\> "\<%{POSINT:syslog\_pri}\>% %{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
> add\_field =\> ["received\_at", "%{@timestamp}"]  
> add\_field =\> ["received\_from", "%{host}"]  
> }  
> syslog\_pri { }  
> date {  
> match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
> }  
> }  
> }

I freely admit that I don't fully understand grok to the point that I know how to extract the proper priority fileds.

Also in Kibana when I try to do a visualization, the syslog\_priority fields aren't showing up as fields I can use to split up pie charts and such.

Any help is very greatly appreciated. Thank you.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 22, 2019, 9:55pm UTC](https://discuss.elastic.co/t/all-syslogs-have-same-severity/196390/2 "2019-08-22T21:55:50Z")

</div>

> [@jmorris](#):
>
> all 500 of them came over as 'notice' and '5'.

Those are the default values if the syslog\_pri field does not exist. Are you sure your grok is working? It look to me like you have an extra % in there.

---

<div class="post-metadata">

**Author:** ![jmorris](https://avatars.discourse-cdn.com/v4/letter/j/ba8739/32.png) [@jmorris](https://discuss.elastic.co/u/jmorris)\
**Post date:** [August 23, 2019, 10:28am UTC](https://discuss.elastic.co/t/all-syslogs-have-same-severity/196390/3 "2019-08-23T10:28:32Z")

</div>

Would you mind pointing out the extra % sign? As I said above, I dont grok grok.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 23, 2019, 1:59pm UTC](https://discuss.elastic.co/t/all-syslogs-have-same-severity/196390/4 "2019-08-23T13:59:53Z")

</div>

> [@jmorris](#):
>
> \<%{POSINT:syslog\_pri}\>% %{SYSLOGTIMESTAMP:syslog\_timestamp}

You have a % after the closing \> that probably should not be there. You may not want a space there either.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 20, 2019, 2:06pm UTC](https://discuss.elastic.co/t/all-syslogs-have-same-severity/196390/5 "2019-09-20T14:06:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
