# Filebeat syslog input : enable both TCP + UDP on port 514

**URL:** <https://discuss.elastic.co/t/filebeat-syslog-input-enable-both-tcp-udp-on-port-514/228671>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 18, 2020, 6:19pm UTC](https://discuss.elastic.co/t/filebeat-syslog-input-enable-both-tcp-udp-on-port-514/228671 "2020-04-18T18:19:41Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![webfr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webfr/32/87580_2.png) [@webfr](https://discuss.elastic.co/u/webfr)\
**Post date:** [April 18, 2020, 6:19pm UTC](https://discuss.elastic.co/t/filebeat-syslog-input-enable-both-tcp-udp-on-port-514/228671/1 "2020-04-18T18:19:42Z")

</div>

Hello guys,  
I can't enable BOTH protocols on port 514 with settings below in filebeat.yml  
Does this input only support one protocol at a time? Nothing is written if I enable both protocols, I also tried with different ports. Filebeat directly connects to ES.

> ```
> # Syslog input
> filebeat.inputs:
> - type: syslog
> enabled: true
> max_message_size: 10KiB
> keep_null: true
> timeout: 10
> protocol.udp:
> host: "myhost.net:514"
> 
> filebeat.inputs:
> - type: syslog
> enabled: true
> max_message_size: 10KiB
> timeout: 10
> keep_null: true
> protocol.tcp:
> host: "myhost.net:514"
> 
> ```

Log:  
2020-04-18T20:39:12.200+0200 INFO [syslog] syslog/input.go:155 Starting Syslog input {"protocol": "tcp"}  
nothing in log regarding udp.

Thanks for your help.

---

<div class="post-metadata">

**Author:** ![shaunak](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/shaunak/32/6643_2.png) [@shaunak](https://discuss.elastic.co/u/shaunak)\
**Post date:** [April 21, 2020, 10:05am UTC](https://discuss.elastic.co/t/filebeat-syslog-input-enable-both-tcp-udp-on-port-514/228671/2 "2020-04-21T10:05:04Z")

</div>

The problem might be that you have two `filebeat.inputs:` sections. How about something like the following instead?

```auto
# Syslog input
filebeat.inputs:
- type: syslog
  enabled: true
  max_message_size: 10KiB
  keep_null: true
  timeout: 10
  protocol.udp:
    host: "myhost.net:514"

- type: syslog
  enabled: true
  max_message_size: 10KiB
  timeout: 10
  keep_null: true
  protocol.tcp:
    host: "myhost.net:514"

```

---

<div class="post-metadata">

**Author:** ![webfr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/webfr/32/87580_2.png) [@webfr](https://discuss.elastic.co/u/webfr)\
**Post date:** [April 21, 2020, 1:34pm UTC](https://discuss.elastic.co/t/filebeat-syslog-input-enable-both-tcp-udp-on-port-514/228671/3 "2020-04-21T13:34:32Z")

</div>

It works, thanks 🙂

2020-04-21T15:14:32.017+0200 INFO [syslog] syslog/input.go:155 Starting Syslog input {"protocol": "tcp"}  
2020-04-21T15:14:32.018+0200 INFO [syslog] syslog/input.go:155 Starting Syslog input {"protocol": "udp"}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 19, 2020, 1:34pm UTC](https://discuss.elastic.co/t/filebeat-syslog-input-enable-both-tcp-udp-on-port-514/228671/4 "2020-05-19T13:34:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
