# Filebeat filtering incoming syslogs?

**URL:** <https://discuss.elastic.co/t/filebeat-filtering-incoming-syslogs/342458>\
**Category:** Elasticsearch\
**Created:** [September 6, 2023, 2:50pm UTC](https://discuss.elastic.co/t/filebeat-filtering-incoming-syslogs/342458 "2023-09-06T14:50:39Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [September 6, 2023, 2:50pm UTC](https://discuss.elastic.co/t/filebeat-filtering-incoming-syslogs/342458/1 "2023-09-06T14:50:39Z")

</div>

I'm setting up Filebeat (8.9) on an Elasticsearch (8.9) instance, and it looks like Filebeat is filtering logs from external hosts.

Here's the relevant section from my Filebeat config:

```auto
- type: syslog
  format: auto
  protocol.udp:
    host: "0.0.0.0:9002"

```

It appears the port is open: `sudo netstat -nulp` shows this:

```auto
Active Internet connections (only servers)
Proto Recv-Q Send-Q Local Address Foreign Address State PID/Program name
udp 0 0 127.0.0.53:53 0.0.0.0:* 1216/systemd-resolv
udp6 0 0 :::9002 :::* 1687881/filebeat

```

Curiously, however, ss doesn't show the port being open: `sudo ss -ltn` shows:

```auto
State Recv-Q Send-Q Local Address:Port Peer Address:Port Process
LISTEN 0 4096 127.0.0.53%lo:53 0.0.0.0:*
LISTEN 0 128 0.0.0.0:22 0.0.0.0:*
LISTEN 0 100 0.0.0.0:25 0.0.0.0:*
LISTEN 0 511 0.0.0.0:5601 0.0.0.0:*
LISTEN 0 4096 *:9200 *:*
LISTEN 0 4096 *:27761 *:*
LISTEN 0 4096 *:27762 *:*
LISTEN 0 4096 *:27763 *:*
LISTEN 0 4096 [::ffff:127.0.0.1]:9300 *:*
LISTEN 0 4096 [::1]:9300 [::]:*
LISTEN 0 4096 *:27764 *:*
LISTEN 0 4096 *:27765 *:*
LISTEN 0 4096 *:27766 *:*
LISTEN 0 128 [::]:22 [::]:*
LISTEN 0 4096 *:27767 *:*
LISTEN 0 4096 *:27768 *:*
LISTEN 0 100 [::]:25 [::]:*

```

I can send a message to myself: `echo "test" | nc -w1 -u 127.0.0.1 9002`

When I do this, I can see the log showing up in `filebeat -e -d "*"` and in the Discover GUI.

However, when I send real traffic from another host, nothing shows up. I can see that the packet is being received:

```auto
sudo tcpdump -n 'udp port 9002'
tcpdump: verbose output suppressed, use -v[v]... for full protocol decode
listening on eno2, link-type EN10MB (Ethernet), snapshot length 262144 bytes
14:37:14.925978 IP [external host IP].52936 > [filebeat server IP].9002: UDP, length 102

```

What am I missing?

---

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [September 6, 2023, 3:44pm UTC](https://discuss.elastic.co/t/filebeat-filtering-incoming-syslogs/342458/2 "2023-09-06T15:44:34Z")

</div>

One thing to add: When I scan the host with nmap, the port I'm using (9002 UDP) is shown as `open|filtered`

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [September 6, 2023, 8:50pm UTC](https://discuss.elastic.co/t/filebeat-filtering-incoming-syslogs/342458/3 "2023-09-06T20:50:33Z")

</div>

It looks like you have to check firewall rule for UDP 9002.

---

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [September 8, 2023, 6:30pm UTC](https://discuss.elastic.co/t/filebeat-filtering-incoming-syslogs/342458/4 "2023-09-08T18:30:13Z")

</div>

There's no network firewall between the two hosts, and since I can see the incoming test traffic with `tcpdump`, that leaves a host firewall. I'm using Ubuntu, which ships with `ufw`. - it shows:

```auto
Status: active

To Action From
-- ------ ----
9002 ALLOW Anywhere
5601 ALLOW Anywhere
22 ALLOW Anywhere
9200 ALLOW Anywhere
9002 (v6) ALLOW Anywhere (v6)
5601 (v6) ALLOW Anywhere (v6)
22 (v6) ALLOW Anywhere (v6)
9200 (v6) ALLOW Anywhere (v6)

```

Which seems to indicate that 9002 UDP is open.

---

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [September 8, 2023, 6:33pm UTC](https://discuss.elastic.co/t/filebeat-filtering-incoming-syslogs/342458/5 "2023-09-08T18:33:15Z")

</div>

Also, `iptables` also shows 9002 UDP is open:

```auto
 sudo iptables -L -v -n | more | grep 9002
    0 0 ACCEPT tcp -- * * 0.0.0.0/0 0.0.0.0/0 tcp dpt:9002
    0 0 ACCEPT udp -- * * 0.0.0.0/0 0.0.0.0/0 udp dpt:9002

```

---

<div class="post-metadata">

**Author:** ![artschooldropout](https://avatars.discourse-cdn.com/v4/letter/a/8491ac/32.png) [@artschooldropout](https://discuss.elastic.co/u/artschooldropout)\
**Post date:** [September 8, 2023, 7:16pm UTC](https://discuss.elastic.co/t/filebeat-filtering-incoming-syslogs/342458/6 "2023-09-08T19:16:01Z")

</div>

I'm sorry to report that this works now. I am sorry because I don't have any lessons to help anyone reading this in the future! Thank you @Rios for your help!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 6, 2023, 7:16pm UTC](https://discuss.elastic.co/t/filebeat-filtering-incoming-syslogs/342458/7 "2023-10-06T19:16:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
