# Filter syslog messages via priority

**URL:** <https://discuss.elastic.co/t/filter-syslog-messages-via-priority/219190>\
**Category:** Logstash\
**Created:** [February 13, 2020, 11:32am UTC](https://discuss.elastic.co/t/filter-syslog-messages-via-priority/219190 "2020-02-13T11:32:48Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![ptselios](https://avatars.discourse-cdn.com/v4/letter/p/58956e/32.png) [@ptselios](https://discuss.elastic.co/u/ptselios)\
**Post date:** [February 13, 2020, 11:32am UTC](https://discuss.elastic.co/t/filter-syslog-messages-via-priority/219190/1 "2020-02-13T11:32:48Z")

</div>

Hello,  
Currently I have logstash as a centralized syslog server.  
I want to send to Elasticsearch only syslog messages with priority warn and above.  
So, I create the following configuration file:

```
input {
  tcp {
    port => 5514
    type => syslog
  }
  udp {
    port => 5514
    type => syslog
  }
}

# Apply some filters
filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}
## Send the message to Elasticsearch
output {
  if [syslog_severity_code]<5 {
    elasticsearch {
      hosts => ['http://localhost:9200']
      index => "syslog-%{+YYYY.MM.dd}"
      document_type => "system_logs"
    }
  }
}   

```

However, all I get is this error message in the logs:

```
[2020-02-13T12:18:17,156][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600}
[2020-02-13T12:18:17,859][ERROR][org.logstash.execution.WorkerLoop][main] Exception in pipelineworker, the pipeline stopped processing new events, please check your filter configuration and restart Logstash.
java.lang.NullPointerException: null

```

Removing the if... everything works as expected.  
Is there anything wrong with this condition?  
If so, how can I send to ES only the messages with severity higher than warn?

Thank you,

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 13, 2020, 1:40pm UTC](https://discuss.elastic.co/t/filter-syslog-messages-via-priority/219190/2 "2020-02-13T13:40:33Z")

</div>

Where does [syslog\_severity\_code] get set?

---

<div class="post-metadata">

**Author:** ![ptselios](https://avatars.discourse-cdn.com/v4/letter/p/58956e/32.png) [@ptselios](https://discuss.elastic.co/u/ptselios)\
**Post date:** [February 13, 2020, 2:30pm UTC](https://discuss.elastic.co/t/filter-syslog-messages-via-priority/219190/3 "2020-02-13T14:30:00Z")

</div>

This is a very good question, honestly.  
I just used this index/field or whatever, from the logstash output, like for example here: [https://www.elastic.co/guide/en/logstash/current/config-examples.html](https://www.elastic.co/guide/en/logstash/current/config-examples.html)

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 13, 2020, 3:59pm UTC](https://discuss.elastic.co/t/filter-syslog-messages-via-priority/219190/4 "2020-02-13T15:59:13Z")

</div>

The documentation is not correct. [syslog\_severity\_code] would not get set unless the syslog\_pri filter is called.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 12, 2020, 3:59pm UTC](https://discuss.elastic.co/t/filter-syslog-messages-via-priority/219190/5 "2020-03-12T15:59:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
