# Config Logstash for Syslog

**URL:** <https://discuss.elastic.co/t/config-logstash-for-syslog/77325>\
**Category:** Logstash\
**Created:** [March 3, 2017, 2:53pm UTC](https://discuss.elastic.co/t/config-logstash-for-syslog/77325 "2017-03-03T14:53:53Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Senninp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/senninp/32/12409_2.png) [@Senninp](https://discuss.elastic.co/u/Senninp)\
**Post date:** [March 3, 2017, 2:53pm UTC](https://discuss.elastic.co/t/config-logstash-for-syslog/77325/1 "2017-03-03T14:53:53Z")

</div>

Hi everyone,

I would like to know here is my mistake.

My config is :  
Kibana 4.1.1  
Elasticsearch 1.7.1  
Logstash 1.5.4

I want to catch syslog in my elasticsearch. To do this i configure my logstash like :

```
input {
  tcp {
    port => 514
    type => syslog
  }

  udp {
    port => 514
    type => syslog
  }
}

filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    syslog_pri { }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}

output {
    elasticsearch {
        hosts => ["MYSERVER:9200"]
        index => "syslog-%{+YYYY.MM.dd}"
    }
}

```

But when i go on Kibana i have :

 ![](https://us1.discourse-cdn.com/elastic/original/3X/d/a/da20e473c2a5170520215a133352ed3c1b863db8.JPG)

My syslog come from switch, vcenter, and software who generate syslog. I have always the error.

Thank you for your help,

John

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [March 3, 2017, 6:43pm UTC](https://discuss.elastic.co/t/config-logstash-for-syslog/77325/2 "2017-03-03T18:43:14Z")

</div>

What's your question?

---

<div class="post-metadata">

**Author:** ![Senninp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/senninp/32/12409_2.png) [@Senninp](https://discuss.elastic.co/u/Senninp)\
**Post date:** [March 6, 2017, 10:56am UTC](https://discuss.elastic.co/t/config-logstash-for-syslog/77325/3 "2017-03-06T10:56:05Z")

</div>

Why all messages from my syslog are : tags: \_grokparsefailure ?

I would like to see the content of the syslog messages.

---

<div class="post-metadata">

**Author:** ![ZillaG](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/zillag/32/10505_2.png) [@ZillaG](https://discuss.elastic.co/u/ZillaG)\
**Post date:** [March 6, 2017, 8:58pm UTC](https://discuss.elastic.co/t/config-logstash-for-syslog/77325/4 "2017-03-06T20:58:26Z")

</div>

When you use the [Grok debugger](http://grokdebug.herokuapp.com/), does your Grok filter work?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 7, 2017, 6:58am UTC](https://discuss.elastic.co/t/config-logstash-for-syslog/77325/5 "2017-03-07T06:58:28Z")

</div>

I think you have more configuration than you're telling us. The filters you list above aren't used at all since the type of your example messages is "testsyslog" and not "syslog". How come, when the configuration you posted doesn't contain the word "testsyslog"? Which grok filter is adding the `_grokparsefailure` tag?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 4, 2017, 6:58am UTC](https://discuss.elastic.co/t/config-logstash-for-syslog/77325/6 "2017-04-04T06:58:36Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
