# Does Filebeat need logstash to process syslog headers?

**URL:** <https://discuss.elastic.co/t/does-filebeat-need-logstash-to-process-syslog-headers/58313>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 18, 2016, 5:54am UTC](https://discuss.elastic.co/t/does-filebeat-need-logstash-to-process-syslog-headers/58313 "2016-08-18T05:54:39Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![PandKing](https://avatars.discourse-cdn.com/v4/letter/p/258eb7/32.png) [@PandKing](https://discuss.elastic.co/u/PandKing)\
**Post date:** [August 18, 2016, 5:54am UTC](https://discuss.elastic.co/t/does-filebeat-need-logstash-to-process-syslog-headers/58313/1 "2016-08-18T05:54:39Z")

</div>

On my second day of searching for a minimalist solution.

I can get syslog data directly into ES using filebeat but none of the syslog headers are getting parsed so it's kind of useless.

Do I need to use logstash for this job.

Using at home 5a at home an work lab if it matters.

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [August 18, 2016, 6:46am UTC](https://discuss.elastic.co/t/does-filebeat-need-logstash-to-process-syslog-headers/58313/2 "2016-08-18T06:46:06Z")

</div>

FileBeat does not do any processing of log messages, so it often makes sense to send them to Logstash for processing and parsing. In Elasticsearch 5.0 we are however introducing the concept of an [ingest node](https://www.elastic.co/guide/en/elasticsearch/reference/master/ingest.html). This will be able to parse and process messages prior to indexing, and will therefore make it easier to connect FileBeat directly to Elasticsearch for some use cases.

---

<div class="post-metadata">

**Author:** ![PandKing](https://avatars.discourse-cdn.com/v4/letter/p/258eb7/32.png) [@PandKing](https://discuss.elastic.co/u/PandKing)\
**Post date:** [August 18, 2016, 4:27pm UTC](https://discuss.elastic.co/t/does-filebeat-need-logstash-to-process-syslog-headers/58313/3 "2016-08-18T16:27:42Z")

</div>

Thanks Christian,

So it sounds like I would want to run an ingest instance on my syslog server which would tag up the syslog data in real time and also accept beats traffic from clients?  
Trying to understand the deployment model [ES.co](http://ES.co) is building.

WS Webserver  
LH loghost (Runs syslog gateway, filebeat and ingest)  
ES ES Cluster

WS (Apache filebeat) -\> LH -\> ES.  
WS (syslog) -\> LH -\> ES  
Router (syslog) -\> (LH) -\> ES

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 8, 2016, 5:54am UTC](https://discuss.elastic.co/t/does-filebeat-need-logstash-to-process-syslog-headers/58313/4 "2016-09-08T05:54:46Z")

</div>

This topic was automatically closed after 21 days. New replies are no longer allowed.
