# Filebeat vs logstash for syslog

**URL:** <https://discuss.elastic.co/t/filebeat-vs-logstash-for-syslog/196123>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 21, 2019, 1:26pm UTC](https://discuss.elastic.co/t/filebeat-vs-logstash-for-syslog/196123 "2019-08-21T13:26:28Z")\
**Posts on this page:** 1\
**Showing post:** 3

<div class="post-metadata">

**Author:** ![Justin\_Doles](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/justin_doles/32/40730_2.png) [@Justin\_Doles](https://discuss.elastic.co/u/Justin_Doles)\
**Post date:** [August 22, 2019, 1:49pm UTC](https://discuss.elastic.co/t/filebeat-vs-logstash-for-syslog/196123/3 "2019-08-22T13:49:34Z")

</div>

Thanks @rugenl . I did find a deal breaker for filebeat & syslog in our environment. Filebeat seems to treat all syslogs sent to it as if they were created by the host it's running on. That kind of defeats the purpose. [All syslogs appear to come from the same host](https://discuss.elastic.co/t/all-syslogs-appear-to-come-from-the-same-host/196119)

So it looks like I'm back to Logstash. I was really hoping to use the modules as they do simply just work like you stated.

---

_[View the full topic](https://discuss.elastic.co/t/filebeat-vs-logstash-for-syslog/196123)._
