# Filebeat vs logstash for syslog

**URL:** <https://discuss.elastic.co/t/filebeat-vs-logstash-for-syslog/196123>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 21, 2019, 1:26pm UTC](https://discuss.elastic.co/t/filebeat-vs-logstash-for-syslog/196123 "2019-08-21T13:26:28Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Justin\_Doles](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_doles/32/40730_2.png) [@Justin\_Doles](https://discuss.elastic.co/u/Justin_Doles)\
**Post date:** [August 21, 2019, 1:26pm UTC](https://discuss.elastic.co/t/filebeat-vs-logstash-for-syslog/196123/1 "2019-08-21T13:26:28Z")

</div>

I've been using logstash to test ingesting logs from various network devices (mostly Cisco). It works well. I see that filebeat has support for syslog ingestion and specifically includes a Cisco module.

I can't seem to find the benefits of using filebeat over logstash for syslog. Are there capabilities that filebeat has that logstash doesn't? In my test bed, I have all my beats (packet, win, etc) sending to a logstash instance which passes it along to ES. In my test case using filebeat wouldn't eliminate logstash. I am using Elastic Common Schema which the beats seem to support out of the box.

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [August 22, 2019, 2:57am UTC](https://discuss.elastic.co/t/filebeat-vs-logstash-for-syslog/196123/2 "2019-08-22T02:57:09Z")

</div>

In a linux world, filebeat reads logs written by rsyslog (or syslog service of choice) vs. rsyslog sending over udp (or tcp) syslog protocol which logstash can process.

CONS:

1. If your disk breaks, you can't log, filebeat can's send logs
2. You have to read various log files
3. Some "appliances" and most hardware won't let you install filebeat, the agent is required.

PROS:

1. If filebeat can't send, it will pickup where it left off from the files.
2. filebeat modules "just work" for parsing even into Elastic's new SIEM.
3. filebeat can load balance output to a list of redundant ingesting servers.
4. If you need to add a non-syslog log (apache), filebeat is needed anyway.

---

<div class="post-metadata">

**Author:** ![Justin\_Doles](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_doles/32/40730_2.png) [@Justin\_Doles](https://discuss.elastic.co/u/Justin_Doles)\
**Post date:** [August 22, 2019, 1:49pm UTC](https://discuss.elastic.co/t/filebeat-vs-logstash-for-syslog/196123/3 "2019-08-22T13:49:34Z")

</div>

Thanks @rugenl . I did find a deal breaker for filebeat & syslog in our environment. Filebeat seems to treat all syslogs sent to it as if they were created by the host it's running on. That kind of defeats the purpose. [All syslogs appear to come from the same host](https://discuss.elastic.co/t/all-syslogs-appear-to-come-from-the-same-host/196119)

So it looks like I'm back to Logstash. I was really hoping to use the modules as they do simply just work like you stated.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 19, 2019, 1:49pm UTC](https://discuss.elastic.co/t/filebeat-vs-logstash-for-syslog/196123/4 "2019-09-19T13:49:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
