# Differentiate Linux syslog log from Windows event log

**URL:** <https://discuss.elastic.co/t/differentiate-linux-syslog-log-from-windows-event-log/215449>\
**Category:** Logstash\
**Created:** [January 17, 2020, 11:34am UTC](https://discuss.elastic.co/t/differentiate-linux-syslog-log-from-windows-event-log/215449 "2020-01-17T11:34:23Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![claud81](https://avatars.discourse-cdn.com/v4/letter/c/a87d85/32.png) [@claud81](https://discuss.elastic.co/u/claud81)\
**Post date:** [January 17, 2020, 11:34am UTC](https://discuss.elastic.co/t/differentiate-linux-syslog-log-from-windows-event-log/215449/1 "2020-01-17T11:34:23Z")

</div>

Hi everyone,

we have 2 conf file in Logstash (version 6.8.6) conf.d directory to differentiate Microsoft log from Linux log, the first:

```
input {
       tcp {
              port => 3515
              codec => json
              }
      }
filter {
        mutate {
                 add_tag => ["forwardedevtx"]
               }
       }
output
       {
       elasticsearch {
                      hosts => ["nodeX:9200", "nodeX:9200", "nodeX:9200"]
                      index => "forwardedevtx-%{+YYYY.MM.dd}"
                     }
       }

```

the second:

```
input {
  tcp {
    port => 5000
    type => syslog
  }
}
filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    syslog_pri { }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
    mutate {
             add_tag => ["forwardedsyslog"]
           }

  }
}
output {
  elasticsearch { 
		  hosts => ["nodeX:9200", "nodeX:9200", "nodeX:9200"]
		  index => "forwardedsyslog-%{+YYYY.MM.dd}"
		}
}

```

I can't explain why in Kibana I can't see this difference, if I select forwardedsyslog or forwardedevtx index pattern I see all the logs, both Microsoft and Linux.

I would like to have into forwardedsyslog index only the Linux one, and into forwardedevtx only the Microsoft one, what am I missing?

Thanks! 🙂

---

<div class="post-metadata">

**Author:** ![grumo35](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/grumo35/32/59451_2.png) [@grumo35](https://discuss.elastic.co/u/grumo35)\
**Post date:** [January 17, 2020, 1:19pm UTC](https://discuss.elastic.co/t/differentiate-linux-syslog-log-from-windows-event-log/215449/2 "2020-01-17T13:19:34Z")

</div>

Before each output please include an if statement

if "forwardedsyslog" in [tags] {  
output ...  
}

---

<div class="post-metadata">

**Author:** ![claud81](https://avatars.discourse-cdn.com/v4/letter/c/a87d85/32.png) [@claud81](https://discuss.elastic.co/u/claud81)\
**Post date:** [January 17, 2020, 1:40pm UTC](https://discuss.elastic.co/t/differentiate-linux-syslog-log-from-windows-event-log/215449/3 "2020-01-17T13:40:08Z")

</div>

Hi grumo35,

thanks for your reply.  
I'll give it a try and let you know 🙂

---

<div class="post-metadata">

**Author:** ![claud81](https://avatars.discourse-cdn.com/v4/letter/c/a87d85/32.png) [@claud81](https://discuss.elastic.co/u/claud81)\
**Post date:** [January 17, 2020, 2:23pm UTC](https://discuss.elastic.co/t/differentiate-linux-syslog-log-from-windows-event-log/215449/4 "2020-01-17T14:23:15Z")

</div>

> [@grumo35](#):
>
> Before each output please include an if statement
> 
> if "forwardedsyslog" in [tags] {  
> output ...  
> }

Here are my new conf file, but nothing as changed:

```
input {
       tcp {
              port => 3515
              codec => json
              }
}
filter {
        mutate {
                 add_tag => ["forwardedevtx"]
               }
}
output {
  if "forwardedevtx" in [tags] {
    elasticsearch {
                    hosts => ["nodeX:9200", "nodeX:9200", "nodeX:9200"]
                    index => "forwardedevtx-%{+YYYY.MM.dd}"
                  }
  }
}

```

and:

```
input {
  tcp {
    port => 5000
    type => syslog
  }
}
filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    syslog_pri { }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
    mutate {
             add_tag => ["forwardedsyslog"]
           }

  }
}
output {
  if "forwardedsyslog" in [tags] {
    elasticsearch {
		    hosts => ["nodeX:9200", "nodeX:9200", "nodeX:9200"]
		    index => "forwardedsyslog-%{+YYYY.MM.dd}"
    }
  }
}

```

I can see all logs mixed both in forwardedsyslog and forwardedevtx index patterns into Kibana.  
In addition, I wonder if we're collecting doubled logs into index patterns, both Microsoft and Linux logs are going into each different index??

Thanks 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 17, 2020, 2:44pm UTC](https://discuss.elastic.co/t/differentiate-linux-syslog-log-from-windows-event-log/215449/5 "2020-01-17T14:44:25Z")

</div>

Does [this](https://discuss.elastic.co/t/logstash-jdbc-and-firebird/213393/3) help?

---

<div class="post-metadata">

**Author:** ![claud81](https://avatars.discourse-cdn.com/v4/letter/c/a87d85/32.png) [@claud81](https://discuss.elastic.co/u/claud81)\
**Post date:** [January 17, 2020, 3:43pm UTC](https://discuss.elastic.co/t/differentiate-linux-syslog-log-from-windows-event-log/215449/6 "2020-01-17T15:43:32Z")

</div>

> [@Badger](#):
>
> Does [this](https://discuss.elastic.co/t/logstash-jdbc-and-firebird/213393/3) help?

thanks for your reply!  
I'll take a look into it!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 14, 2020, 3:43pm UTC](https://discuss.elastic.co/t/differentiate-linux-syslog-log-from-windows-event-log/215449/7 "2020-02-14T15:43:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
