# Filebeat haproxy module

**URL:** <https://discuss.elastic.co/t/filebeat-haproxy-module/159629>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [December 6, 2018, 12:56am UTC](https://discuss.elastic.co/t/filebeat-haproxy-module/159629 "2018-12-06T00:56:05Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Mark\_Bassett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_bassett/32/45353_2.png) [@Mark\_Bassett](https://discuss.elastic.co/u/Mark_Bassett)\
**Post date:** [December 6, 2018, 12:56am UTC](https://discuss.elastic.co/t/filebeat-haproxy-module/159629/1 "2018-12-06T00:56:05Z")

</div>

What is the correct method to get logs to the filebeat haproxy module? I see it is running udp syslog on port 9001 so I just added

log 127.0.0.1:9001 local0 notice

under the global section, but it looks like it is not expecting syslog type logs with facility/priority?

\<133\>Dec 6 00:27:54 haproxy[10946]: Health check for server succeeded, reason: Layer7 check passed, code: 200, info: "OK", check duration: 8ms, status: 3/3 UP.

Provided Grok expressions do not match field value:

---

<div class="post-metadata">

**Author:** ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)\
**Post date:** [December 6, 2018, 1:16pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module/159629/2 "2018-12-06T13:16:28Z")

</div>

Filebeat syslog parser does not support RFC5424 yet. See issue [#6872](https://github.com/elastic/beats/issues/6872). I guess this is what your HAProxy is sending.

---

<div class="post-metadata">

**Author:** ![Mark\_Bassett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_bassett/32/45353_2.png) [@Mark\_Bassett](https://discuss.elastic.co/u/Mark_Bassett)\
**Post date:** [December 6, 2018, 7:00pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module/159629/3 "2018-12-06T19:00:08Z")

</div>

I'm wondering if this is related to

> [@Typo in syslog\_rfc3164.rl causes parsing errors for December syslog dates](https://discuss.elastic.co/t/typo-in-syslog-rfc3164-rl-causes-parsing-errors-for-december-syslog-dates/159030):
>
> For confirmed bugs, please report: Version: 6.3.2 Operating System: FreeBSD GitHub Link: [https://github.com/elastic/beats/issues/9323](https://github.com/elastic/beats/issues/9323) Steps to Reproduce: With the system clock on the computer where filebeat is installed set to the month of December, attempt to ingest a syslog message using the syslog input plugin. These are the errors I get: 2018-12-02T07:38:44.727Z ERROR [syslog] syslog/input.go:114 can't not parse event as syslog rfc3164 {"message": "Dec 02 07:38:44 freebsd-11-2 crontab[81…

---

<div class="post-metadata">

**Author:** ![Mark\_Bassett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_bassett/32/45353_2.png) [@Mark\_Bassett](https://discuss.elastic.co/u/Mark_Bassett)\
**Post date:** [December 6, 2018, 7:13pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module/159629/4 "2018-12-06T19:13:49Z")

</div>

My haproxy is configured to use rfc3164 log output, but the syslog facility and priority its logging is throwing it off.

#configured as rfc3164  
2018-12-06T19:12:55.360Z ERROR [syslog] syslog/input.go:131 can't not parse event as syslog rfc3164 {"message": "\<133\>Dec 6 19:12:55 haproxy[18524]: Proxy LBRGS-SBX started.\n"}

#configured as rfc5424  
2018-12-06T19:10:16.134Z ERROR [syslog] syslog/input.go:131 can't not parse event as syslog rfc3164 {"message": "\<133\>1 2018-12-06T19:10:16+00:00 lbrgs01 haproxy 18461 - - Proxy LBRGS-SBX started.\n"}

---

<div class="post-metadata">

**Author:** ![bigphil](https://avatars.discourse-cdn.com/v4/letter/b/65b543/32.png) [@bigphil](https://discuss.elastic.co/u/bigphil)\
**Post date:** [December 6, 2018, 7:30pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module/159629/5 "2018-12-06T19:30:05Z")

</div>

I think you had it correct. It appears to be the bug you had previously linked (Filebeat syslog parser Dec bug). The facility and severity look good to me in your rfc3164 message. local0 x8 + notice (16x8) +5 = 133.

---

<div class="post-metadata">

**Author:** ![Mark\_Bassett](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/mark_bassett/32/45353_2.png) [@Mark\_Bassett](https://discuss.elastic.co/u/Mark_Bassett)\
**Post date:** [December 6, 2018, 8:22pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module/159629/6 "2018-12-06T20:22:55Z")

</div>

Looks like that update hasn't made it to release yet. appears to be included with 6.5.3

> **[elastic/beats](https://github.com/elastic/beats/compare/v6.5.2...6.5)**
>
> :tropical\_fish: Beats - Lightweight shippers for Elasticsearch & Logstash - elastic/beats

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 3, 2019, 8:36pm UTC](https://discuss.elastic.co/t/filebeat-haproxy-module/159629/7 "2019-01-03T20:36:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
