# \[BUG\] Filebeat is unable to parse the syslog message when priority value is given as \<0\> in syslog message of format RFC 3164

**URL:** <https://discuss.elastic.co/t/bug-filebeat-is-unable-to-parse-the-syslog-message-when-priority-value-is-given-as-0-in-syslog-message-of-format-rfc-3164/170447>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [March 1, 2019, 7:18am UTC](https://discuss.elastic.co/t/bug-filebeat-is-unable-to-parse-the-syslog-message-when-priority-value-is-given-as-0-in-syslog-message-of-format-rfc-3164/170447 "2019-03-01T07:18:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Debashis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debashis/32/45290_2.png) [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Post date:** [March 1, 2019, 7:18am UTC](https://discuss.elastic.co/t/bug-filebeat-is-unable-to-parse-the-syslog-message-when-priority-value-is-given-as-0-in-syslog-message-of-format-rfc-3164/170447/1 "2019-03-01T07:18:05Z")

</div>

**Observation:**  
It is observed that filebeat is unable to parse the syslog message of format RFC-3164 properly when priority value is given as \<0\> in syslog message. For other priorities filebeat is working as expected.

For the above reason filebeat syslog input will never able to parse syslog of Emergency kernal messages.

This is a _ **major bug** _ of filebeat syslog input plugin

**Verification Version:**  
6.4.1 and 6.6.x

**Execution Steps:**  
1. Enable "syslog" type prospector using "tcp" protocol in "filebeat.yml"  
filebeat.inputs:  
- type: syslog  
enabled: true  
protocol.tcp:  
host: "localhost:9000"  
2. Start filebeat  
# filebeat -e  
3. Connect and send data using tcp client to filebeat  
# nc localhost 9000  
\<0\>Oct 11 22:14:15 mymachine su: 'su root' failed for lonvick on /dev/pts/8

**Output observed in "syslog" field of parsed message:**  
...................  
syslog:{}  
...................

**Expected value for "syslog" field of parsed message:**  
....................  
"syslog": {  
"priority": 0,  
"severity\_label": "Emergency",  
"facility": 0,  
"facility\_label": "kernel"  
},  
....................

**Important Note:**  
I have verified this in different filebeat versions as well as in currently stable 6.6.x version. It is not working.

I am able to identify some source code level mistake for the above scenario. I have locally fixed this issue in code and it is working fine.

So I am going to raise an issue in github as well as will upload the patch for the fix.

Kindly let me know for any suggestion.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 1, 2019, 9:26am UTC](https://discuss.elastic.co/t/bug-filebeat-is-unable-to-parse-the-syslog-message-when-priority-value-is-given-as-0-in-syslog-message-of-format-rfc-3164/170447/2 "2019-03-01T09:26:48Z")

</div>

Indeed. Thank you for the report. We would be grateful if you opened a PR with your patch.

---

<div class="post-metadata">

**Author:** ![Debashis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debashis/32/45290_2.png) [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Post date:** [March 1, 2019, 9:29am UTC](https://discuss.elastic.co/t/bug-filebeat-is-unable-to-parse-the-syslog-message-when-priority-value-is-given-as-0-in-syslog-message-of-format-rfc-3164/170447/3 "2019-03-01T09:29:37Z")

</div>

Hi @kvch,  
Thank you for confirmation.

I have raised an issue in github regarding this

> <https://github.com/elastic/beats/issues/11010>

---

<div class="post-metadata">

**Author:** ![Debashis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debashis/32/45290_2.png) [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Post date:** [March 1, 2019, 9:33am UTC](https://discuss.elastic.co/t/bug-filebeat-is-unable-to-parse-the-syslog-message-when-priority-value-is-given-as-0-in-syslog-message-of-format-rfc-3164/170447/4 "2019-03-01T09:33:31Z")

</div>

I have proposed a patch.

The PR is : [https://github.com/elastic/beats/pull/11011](https://github.com/elastic/beats/pull/11011)

Currently it is pending for CLA. I will do this agreement asap.

---

<div class="post-metadata">

**Author:** ![kvch](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kvch/32/72058_2.png) [@kvch](https://discuss.elastic.co/u/kvch)\
**Post date:** [March 1, 2019, 9:47am UTC](https://discuss.elastic.co/t/bug-filebeat-is-unable-to-parse-the-syslog-message-when-priority-value-is-given-as-0-in-syslog-message-of-format-rfc-3164/170447/5 "2019-03-01T09:47:10Z")

</div>

Thank you!

---

<div class="post-metadata">

**Author:** ![Debashis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/debashis/32/45290_2.png) [@Debashis](https://discuss.elastic.co/u/Debashis)\
**Post date:** [March 19, 2019, 6:08am UTC](https://discuss.elastic.co/t/bug-filebeat-is-unable-to-parse-the-syslog-message-when-priority-value-is-given-as-0-in-syslog-message-of-format-rfc-3164/170447/6 "2019-03-19T06:08:34Z")

</div>

I am going to close old pull request because of some base branch mismatch. New pull request is already created and approved by the reviewer.

Old PR : [https://github.com/elastic/beats/pull/11011](https://github.com/elastic/beats/pull/11011)  
New PR: [https://github.com/elastic/beats/pull/11288](https://github.com/elastic/beats/pull/11288)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 16, 2019, 6:08am UTC](https://discuss.elastic.co/t/bug-filebeat-is-unable-to-parse-the-syslog-message-when-priority-value-is-given-as-0-in-syslog-message-of-format-rfc-3164/170447/7 "2019-04-16T06:08:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
