# Difference between input type "syslog" and "tcp"?

**URL:** <https://discuss.elastic.co/t/difference-between-input-type-syslog-and-tcp/108574>\
**Category:** Logstash\
**Created:** [November 21, 2017, 2:40pm UTC](https://discuss.elastic.co/t/difference-between-input-type-syslog-and-tcp/108574 "2017-11-21T14:40:03Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![jcarnat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jcarnat/32/24515_2.png) [@jcarnat](https://discuss.elastic.co/u/jcarnat)\
**Post date:** [November 21, 2017, 2:40pm UTC](https://discuss.elastic.co/t/difference-between-input-type-syslog-and-tcp/108574/1 "2017-11-21T14:40:03Z")

</div>

Hi,

What is the difference between using the syslog and the tcp inputs when dealing with logs?

After reading the 5.6/plugins-inputs-syslog and 5.6/plugins-inputs-tcp pages, I can't guess the pros / cons of each plugins. I also checked 6.0 docs to see if syslog was deprecated but it doesn't seem to.

Any inputs to help deciding why one to use?

Thank you.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 22, 2017, 6:23am UTC](https://discuss.elastic.co/t/difference-between-input-type-syslog-and-tcp/108574/2 "2017-11-22T06:23:23Z")

</div>

The syslog input listens for both UDP and TCP packets and parses most syslog inputs out of the box so that few or no additional filters are needed. The tcp input only does TCP and leaves the syslog parsing to other plugins.

---

<div class="post-metadata">

**Author:** ![jcarnat](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jcarnat/32/24515_2.png) [@jcarnat](https://discuss.elastic.co/u/jcarnat)\
**Post date:** [November 22, 2017, 10:22pm UTC](https://discuss.elastic.co/t/difference-between-input-type-syslog-and-tcp/108574/3 "2017-11-22T22:22:29Z")

</div>

Ok, thanks.

I've tried both to check. Sending them data in RFC-5424 and RFC-3164.  
I have managed to do more things using the tcp input than the syslog.  
Not sure if that's expected. Seemed the syslog input didn't like to get various format.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 20, 2017, 10:22pm UTC](https://discuss.elastic.co/t/difference-between-input-type-syslog-and-tcp/108574/4 "2017-12-20T22:22:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
