# Error parsing syslog input message in Logstash

**URL:** <https://discuss.elastic.co/t/error-parsing-syslog-input-message-in-logstash/172530>\
**Category:** Logstash\
**Created:** [March 15, 2019, 1:11pm UTC](https://discuss.elastic.co/t/error-parsing-syslog-input-message-in-logstash/172530 "2019-03-15T13:11:22Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![lcavator](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lcavator/32/42103_2.png) [@lcavator](https://discuss.elastic.co/u/lcavator)\
**Post date:** [March 15, 2019, 1:11pm UTC](https://discuss.elastic.co/t/error-parsing-syslog-input-message-in-logstash/172530/1 "2019-03-15T13:11:22Z")

</div>

Hi to all,

I'm trying to parse a syslog message (coming from vmWare Log Insight) to obtain additional fields added inside the message body string, and then send them in json format to a kafka broker.

This is an example message obtained without filter in config file (only syslog input and output on text file with logstash):

{"@timestamp":"2019-03-15T10:01:28.978Z","@version":"1","message":"\<14\>1 2019-03-15T09:52:13.88Z [hostname.fqdn.com](http://hostname.fqdn.com) - - - [Originator@6876 filepath="/path/logs/log.log" application\_type="java" acronimo="xxxx0"] 338796f0-9e99-444a-b955-bba90512db62 2019-03-14 15:18:53,080 log messate text etc...","priority":0,"tags":["\_grokparsefailure\_sysloginput"],"severity\_label":"Emergency","host":"1.1.1.1","facility\_label":"kernel","severity":0,"facility":0}

Using it on **[https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/)** with filter:

^\<%{NUMBER}\>%{NUMBER}\s+%{TIMESTAMP\_ISO8601:date}\s+%{HOSTNAME:src\_hostname}\s+%{DATA}\s+%{DATA}\s+%{DATA}\s+[%{DATA}\s+filepath=\"%{DATA:src\_filepath}\"\s+application\_type=\"%{DATA:application\_type}\"\s+acronimo=\"%{DATA:acronimo}\"]\s(?:%{UUID:loginsight\_id})?%{GREEDYDATA:syslog\_message}$

This is the result:  
{  
"NUMBER": [  
[  
"14",  
"1"  
]  
],  
"BASE10NUM": [  
[  
"14",  
"1"  
]  
],  
"date": [  
[  
"2019-03-15T09:52:13.88Z"  
]  
],  
"YEAR": [  
[  
"2019"  
]  
],  
"MONTHNUM": [  
[  
"03"  
]  
],  
"MONTHDAY": [  
[  
"15"  
]  
],  
"HOUR": [  
[  
"09",  
null  
]  
],  
"MINUTE": [  
[  
"52",  
null  
]  
],  
"SECOND": [  
[  
"13.88"  
]  
],  
"ISO8601\_TIMEZONE": [  
[  
"Z"  
]  
],  
"src\_hostname": [  
[  
"[hostname.fqdn.com](http://hostname.fqdn.com)"  
]  
],  
"DATA": [  
[  
"-",  
"-",  
"-",  
"Originator@6876"  
]  
],  
"src\_filepath": [  
[  
"/path/logs/log.log"  
]  
],  
"application\_type": [  
[  
"java"  
]  
],  
"acronimo": [  
[  
"xxxx0"  
]  
],  
"loginsight\_id": [  
[  
"338796f0-9e99-444a-b955-bba90512db62"  
]  
],  
"syslog\_message": [  
[  
" 2019-03-14 15:18:53,080 log messate text etc..."  
]  
]  
}

I need to keep syslog\_message, acronimo, application\_type and src\_hostname

This is the pipeline configured in logstash

```
input {
  syslog {
    port => 1514
  }
}

filter {
	grok {
		match => {
			"message" => '^<%{NUMBER}>%{NUMBER}\s+%{TIMESTAMP_ISO8601:date}\s+%{HOSTNAME:src_hostname}\s+%{DATA}\s+%{DATA}\s+%{DATA}\s+\[%{DATA}\s+filepath=\\\"%{DATA:src_filepath}\\\"\s+application_type=\\\"%{DATA:application_type}\\\"\s+acronimo=\\\"%{DATA:acronimo}\\\"\]\s(?:%{UUID:loginsight_id})?%{GREEDYDATA:syslog_message}$'
		}
	}
}

output {
  kafka {
    codec => json
    topic_id => "xxxx0"
  }
  stdout {
    codec => "rubydebug"
  }
}

```

This is the result on stdout:

```
"priority" => 0,
"@timestamp" => 2019-03-15T10:01:28.978Z
}
{
"message" => "<14>1 2019-03-15T09:52:13.88Z hostname.fqdn.com - - - [Originator@6876 filepath=\"/path/logs/log.log\" application_type=\"java\" acronimo=\"xxxx0\"] 338796f0-9e99-444a-b955-bba90512db62 2019-03-14 15:18:53,080 log messate text etc...",
"@version" => "1",
"facility_label" => "kernel",
"host" => "1.1.1.1",
"severity" => 0,
"facility" => 0,
"severity_label" => "Emergency",
"tags" => [
[0] "_grokparsefailure_sysloginput",
[1] "_grokparsefailure"
],

```

any idea?  
I'm using logstash v6.6.1 with java version "1.8.0\_162"  
Regards

Luca

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [March 15, 2019, 1:52pm UTC](https://discuss.elastic.co/t/error-parsing-syslog-input-message-in-logstash/172530/2 "2019-03-15T13:52:10Z")

</div>

For the message shown in your post you do not need all the backslashes.

```
'^<%{NUMBER}>%{NUMBER}\s+%{TIMESTAMP_ISO8601:date}\s+%{HOSTNAME:src_hostname}\s+%{DATA}\s+%{DATA}\s+%{DATA}\s+\[%{DATA}\s+filepath="%{DATA:src_filepath}"\s+application_type="%{DATA:application_type}"\s+acronimo="%{DATA:acronimo}"\]\s(?:%{UUID:loginsight_id})?%{GREEDYDATA:syslog_message}$'
```

---

<div class="post-metadata">

**Author:** ![lcavator](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lcavator/32/42103_2.png) [@lcavator](https://discuss.elastic.co/u/lcavator)\
**Post date:** [March 15, 2019, 2:43pm UTC](https://discuss.elastic.co/t/error-parsing-syslog-input-message-in-logstash/172530/3 "2019-03-15T14:43:17Z")

</div>

It works thanks!!!!!!  
On logstash I means  
but not on [https://grokdebug.herokuapp.com/](https://grokdebug.herokuapp.com/). ☹

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 12, 2019, 2:43pm UTC](https://discuss.elastic.co/t/error-parsing-syslog-input-message-in-logstash/172530/4 "2019-04-12T14:43:19Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
