# Filebeat Syslog isn't Opening Port

**URL:** <https://discuss.elastic.co/t/filebeat-syslog-isnt-opening-port/272126>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [May 4, 2021, 11:32pm UTC](https://discuss.elastic.co/t/filebeat-syslog-isnt-opening-port/272126 "2021-05-04T23:32:02Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![odin-bb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/odin-bb/32/88229_2.png) [@odin-bb](https://discuss.elastic.co/u/odin-bb)\
**Post date:** [May 4, 2021, 11:32pm UTC](https://discuss.elastic.co/t/filebeat-syslog-isnt-opening-port/272126/1 "2021-05-04T23:32:03Z")

</div>

Good Afternoon,

First off, thank you for whatever help/suggestions you provide.

I recently posted in the [r/elasticsearch](https://www.reddit.com/r/elasticsearch/comments/n1iqlu/i_need_help_understanding_the_difference_between/gwqkeww/?context=3) trying to understand the difference between logstash and filebeat and was greatly helped by someone on the team. However, as all things do, it spiraled into him helping me troubleshoot and that isn't what he needs to do. So he pointed me here.

I am attempting to setup a local filebeat that acts like a syslog receiver following the instructions here [Syslog input | Filebeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-syslog.html) and [Configure the output | Filebeat Reference [7.12] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/configuring-output.html).

When I add those configurations to my filebeat.yml I see the local syslog traffic in Elastic, but I am not seeing port 9000 (I also tried 514, but that didn't matter really) open to recieve syslog log from other systems. Is my understanding of that wrong? Or did I mess up somewhere?

Here is my filebeat.yml configs.

```
 - type: syslog
   protocol.udp:
   host: "localhost:9000"
 
 # Change to true to enable this input configuration.
 enabled: false
   # Paths that should be crawled and fetched. Glob based paths.
         paths:
      - /var/log/*.log
 output.elasticsearch:
  # Array of hosts to connect to.
   hosts: ["localhost:9200"]
   username: "[redacted]"
   password: "[Redacted]"

```

Again thank you for the help.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 5, 2021, 2:55am UTC](https://discuss.elastic.co/t/filebeat-syslog-isnt-opening-port/272126/2 "2021-05-05T02:55:34Z")

</div>

So it looks like you have input settings for both the syslog and file input as part of the same input.

> [@odin-bb](#):
>
> ```auto
> enabled: false
> # Paths that should be crawled and fetched. Glob based paths.
> paths:
> - /var/log/*.log
> 
> ```

Remove the paths key and path or move it to it's own input. Indent the enabled key to line up with the host key and change to true if u want to use it. Also if u want to listen outside of localhost, change that to `0.0.0.0:9000` to listen on all ips.

---

<div class="post-metadata">

**Author:** ![odin-bb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/odin-bb/32/88229_2.png) [@odin-bb](https://discuss.elastic.co/u/odin-bb)\
**Post date:** [May 5, 2021, 11:15pm UTC](https://discuss.elastic.co/t/filebeat-syslog-isnt-opening-port/272126/3 "2021-05-05T23:15:15Z")

</div>

First off thank you!

Let me see if I get this right.

```
- type: syslog
   protocol.udp:
   host: "0.0.0.0:9000"
 
 # Change to true to enable this input configuration.
    enabled: true
 - type: log
       # Paths that should be crawled and fetched. Glob based paths.
    paths:
          - /var/log/*.log
 output.elasticsearch:
  # Array of hosts to connect to.
   hosts: ["localhost:9200"]
   username: "[redacted]"
   password: "[Redacted]"

```

Is that correct?

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [May 5, 2021, 11:38pm UTC](https://discuss.elastic.co/t/filebeat-syslog-isnt-opening-port/272126/4 "2021-05-05T23:38:11Z")

</div>

Conceptually yes. U still have some uneven indentation that u need to fix. Also if your not actually going to read log files from the system I would comment out those lines.

---

<div class="post-metadata">

**Author:** ![odin-bb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/odin-bb/32/88229_2.png) [@odin-bb](https://discuss.elastic.co/u/odin-bb)\
**Post date:** [May 5, 2021, 11:59pm UTC](https://discuss.elastic.co/t/filebeat-syslog-isnt-opening-port/272126/5 "2021-05-05T23:59:37Z")

</div>

So this is what it should look like?

```
filebeat.inputs:

# Each - is an input. Most options can be set at the input level, so
# you can use different inputs for various configurations.
# Below are the input specific configurations.

- type: syslog
  protocol.udp:
   host: "0.0.0.0:9000"

  # Change to true to enable this input configuration.
  enabled: true

```

I took out the local path for now just trying to get the rest of the syslog working.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 3, 2021, 1:59am UTC](https://discuss.elastic.co/t/filebeat-syslog-isnt-opening-port/272126/6 "2021-06-03T01:59:42Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
