# Can ELK configure Remote Syslog Forwarding to Third party syslog server?

**URL:** <https://discuss.elastic.co/t/can-elk-configure-remote-syslog-forwarding-to-third-party-syslog-server/316953>\
**Category:** Elasticsearch\
**Created:** [October 19, 2022, 6:40am UTC](https://discuss.elastic.co/t/can-elk-configure-remote-syslog-forwarding-to-third-party-syslog-server/316953 "2022-10-19T06:40:34Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![wcpoon](https://avatars.discourse-cdn.com/v4/letter/w/da6949/32.png) [@wcpoon](https://discuss.elastic.co/u/wcpoon)\
**Post date:** [October 19, 2022, 6:40am UTC](https://discuss.elastic.co/t/can-elk-configure-remote-syslog-forwarding-to-third-party-syslog-server/316953/1 "2022-10-19T06:40:34Z")

</div>

Hi All,

Can ELK Stack able to configure remote syslog forwarding to another syslog server?

Kindly please advise.

Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 19, 2022, 8:42am UTC](https://discuss.elastic.co/t/can-elk-configure-remote-syslog-forwarding-to-third-party-syslog-server/316953/2 "2022-10-19T08:42:19Z")

</div>

The Elastic Stack cannot configure a syslog server, no.

You might be able to use Fleet to have Filebeat listen on the syslog port and send to another server though.

---

<div class="post-metadata">

**Author:** ![wcpoon](https://avatars.discourse-cdn.com/v4/letter/w/da6949/32.png) [@wcpoon](https://discuss.elastic.co/u/wcpoon)\
**Post date:** [October 19, 2022, 9:40am UTC](https://discuss.elastic.co/t/can-elk-configure-remote-syslog-forwarding-to-third-party-syslog-server/316953/3 "2022-10-19T09:40:34Z")

</div>

Do you mean, I want to forward the syslog from ELK to splunk or other SIEM product, it is not possible?  
If possible, do you have any guidelines can share with me?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 19, 2022, 9:37pm UTC](https://discuss.elastic.co/t/can-elk-configure-remote-syslog-forwarding-to-third-party-syslog-server/316953/4 "2022-10-19T21:37:40Z")

</div>

What exactly do you want to do?

---

<div class="post-metadata">

**Author:** ![wcpoon](https://avatars.discourse-cdn.com/v4/letter/w/da6949/32.png) [@wcpoon](https://discuss.elastic.co/u/wcpoon)\
**Post date:** [October 20, 2022, 3:13am UTC](https://discuss.elastic.co/t/can-elk-configure-remote-syslog-forwarding-to-third-party-syslog-server/316953/5 "2022-10-20T03:13:58Z")

</div>

Hi,

Currently, most of my syslog will be send over to ELK Stack via logstash / filebeat.  
I want check, whether ELK Stack can forward another copy to remote syslog server (Such as, Splunk, another SIEM)?  
If yes, what should I do to achieve that?

Thanks.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 20, 2022, 3:30am UTC](https://discuss.elastic.co/t/can-elk-configure-remote-syslog-forwarding-to-third-party-syslog-server/316953/6 "2022-10-20T03:30:26Z")

</div>

You can do that with Logstash, using the Elasticsearch input and the rsyslog output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 17, 2022, 3:31am UTC](https://discuss.elastic.co/t/can-elk-configure-remote-syslog-forwarding-to-third-party-syslog-server/316953/7 "2022-11-17T03:31:02Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
