# Filebeat multiple modules on single input syslog port

**URL:** <https://discuss.elastic.co/t/filebeat-multiple-modules-on-single-input-syslog-port/338691>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 18, 2023, 2:17pm UTC](https://discuss.elastic.co/t/filebeat-multiple-modules-on-single-input-syslog-port/338691 "2023-07-18T14:17:27Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Amol\_Sahare](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/amol_sahare/32/122260_2.png) [@Amol\_Sahare](https://discuss.elastic.co/u/Amol_Sahare)\
**Post date:** [July 18, 2023, 2:17pm UTC](https://discuss.elastic.co/t/filebeat-multiple-modules-on-single-input-syslog-port/338691/1 "2023-07-18T14:17:27Z")

</div>

Hi All,

I have installed filebeat Syslog input and received logs from multiple devices like Vmware Esx, Firewall, Unix, VCenter, Antivirus, etc.

Filebeat Yml file:  
fields\_under\_root: true  
fields.collector\_node\_id: ${sidecar.nodeName}  
fields.gl2\_source\_collector: ${sidecar.nodeId}

output.logstash:  
hosts: ["XXX.XXX.XX.XX:XXX"]  
path:  
data: ${sidecar.spoolDir!"C:\Program Files\Graylog\sidecar\cache\filebeat"}\data  
logs: ${sidecar.spoolDir!"C:\Program Files\Graylog\sidecar"}\logs

filebeat.inputs:

- type: syslog  
enabled: true  
keep\_null: true  
format: auto  
timeout: 10  
protocol.udp:  
host: "0.0.0.0:514"

- type: syslog  
enabled: true  
format: auto  
timeout: 10  
keep\_null: true  
protocol.tcp:  
host: "0.0.0.0:514"

I want to use modules to parse all the logs using filebeat. Please let me know how to achieve this.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2023, 4:18pm UTC](https://discuss.elastic.co/t/filebeat-multiple-modules-on-single-input-syslog-port/338691/2 "2023-08-15T16:18:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
