# Auditbeat log to syslog without information

**URL:** <https://discuss.elastic.co/t/auditbeat-log-to-syslog-without-information/356748>\
**Category:** Logstash\
**Created:** [April 4, 2024, 8:27am UTC](https://discuss.elastic.co/t/auditbeat-log-to-syslog-without-information/356748 "2024-04-04T08:27:29Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Roberto3](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/roberto3/32/133258_2.png) [@Roberto3](https://discuss.elastic.co/u/Roberto3)\
**Post date:** [April 4, 2024, 8:27am UTC](https://discuss.elastic.co/t/auditbeat-log-to-syslog-without-information/356748/1 "2024-04-04T08:27:29Z")

</div>

Hi,  
I have a problem to send the audibeat log to my syslog.  
If I send the log to the file inside the file I can show some useful information such as the modified file etc, but If I send the same information to the syslog I receive just few information, and I don't find any way to get more details.

This is my output code:

output {  
syslog {  
host =\> "syslogip"  
protocol =\> udp  
port =\> "port"  
facility =\> "user"  
severity =\> "informational"  
#codec =\> plain { format =\> "%{message}" }  
message =\> "%{message}"  
}  
file {  
path =\> "/tmp/test.log"  
}  
}

I tried removing %message, or adding something else such as a customer string etc but the output still remain the same:

this is an example

\<13\>Apr 03 08:17:47 {"name":"XXXXXXXX","id":"XXXXX","os":{"name":"Red Hat Enterprise Linux Server","family":"redhat","version":"7.6 (Maipo)","platform":"rhel","codename":"Maipo"},"containerized":false,"architecture":"x86\_64"} LOGSTASH[-]: %{message}

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 4, 2024, 4:20pm UTC](https://discuss.elastic.co/t/auditbeat-log-to-syslog-without-information/356748/2 "2024-04-04T16:20:21Z")

</div>

See [this](https://discuss.elastic.co/t/syslog-output-plugin-message-parameter-ignored/352560) thread and read through [this](https://github.com/logstash-plugins/logstash-output-syslog/issues/51) issue.
