# Duplicate everything to syslog

**URL:** <https://discuss.elastic.co/t/duplicate-everything-to-syslog/236926>\
**Category:** Logstash\
**Created:** [June 12, 2020, 5:13pm UTC](https://discuss.elastic.co/t/duplicate-everything-to-syslog/236926 "2020-06-12T17:13:37Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![PangolinCyber](https://avatars.discourse-cdn.com/v4/letter/p/cc9497/32.png) [@PangolinCyber](https://discuss.elastic.co/u/PangolinCyber)\
**Post date:** [June 12, 2020, 5:13pm UTC](https://discuss.elastic.co/t/duplicate-everything-to-syslog/236926/1 "2020-06-12T17:13:37Z")

</div>

I'm trying to put together a system which is intended to tee everything arriving at an ELK system from all input types to an evidence store syslog platform. i.e everything processed by ELK also goes to a syslog in the raw before being processed.

My intended approach is to use the syslog output plugin of logstash, but the examples seem to suggest you have to associate it with each input type individually. Is there a way to introduce a catch-all which forces all logstash inputs to output to this additional syslog destination?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2020, 11:38pm UTC](https://discuss.elastic.co/t/duplicate-everything-to-syslog/236926/2 "2020-07-12T23:38:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
