# Finding data with logstash 7.13.4

**URL:** <https://discuss.elastic.co/t/finding-data-with-logstash-7-13-4/286135>\
**Category:** Logstash\
**Created:** [October 7, 2021, 1:16pm UTC](https://discuss.elastic.co/t/finding-data-with-logstash-7-13-4/286135 "2021-10-07T13:16:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![MKirby](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Post date:** [October 7, 2021, 1:16pm UTC](https://discuss.elastic.co/t/finding-data-with-logstash-7-13-4/286135/1 "2021-10-07T13:16:15Z")

</div>

I have my installation of the ELK stack up and running. All three aspects are running on separate servers but they all communicate and can talk to one another. I have not yet installed any Beats or Security on the installation, however I have forwarded port 514 to a new one so that the Syslogs that are being directed to my Logstash can be collected and seen. After running a tail on the logstash-plain.log I see that UDP Listener started { :address=\>"0.0.0.0:50XX", : receive\_buffer\_bytes=\>"106496", :queue\_size=\>"2000"} .

This makes me secure in believing I have UDP syslogs being collected. Where would I see them on the Logstash server, using Terminal. There is no Desktop interface.

Thank you for any and all assistance.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [October 7, 2021, 3:58pm UTC](https://discuss.elastic.co/t/finding-data-with-logstash-7-13-4/286135/2 "2021-10-07T15:58:54Z")

</div>

What is your question?

---

<div class="post-metadata">

**Author:** ![MKirby](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Post date:** [October 7, 2021, 4:18pm UTC](https://discuss.elastic.co/t/finding-data-with-logstash-7-13-4/286135/3 "2021-10-07T16:18:37Z")

</div>

Hello Badger;

I am trying to see what information, if any is being passed to the Logstash. After speaking to another person the information should be getting to Elasticsearch and of course from there to Kibana where I can run searches through DevTools.

I have followed the following:  
[https://www.elastic.co/guide/en/logstash/current/config-examples.html](https://www.elastic.co/guide/en/logstash/current/config-examples.html)

and added the syslog/udp information into my logstash.conf file. Mostly it is working. Here is the error and my config file for review.

I just want to try and get the information to be seen in my Kibana at this point. before I move on to adding security to my systems.

``'

# Sample Logstash configuration for creating a simple

# Beats -\> Logstash -\> Elasticsearch pipeline.

input {  
beats {  
port =\> 5044  
}  
}

input {  
udp {  
port =\> 5144  
type =\> syslog  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}  
}

output {  
elasticsearch {  
hosts =\> ["[http://192.168.56.9:9200](http://192.168.56.9:9200)"]  
index =\> "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"  
#user =\> "elastic"  
#password =\> "changeme"  
}  
}

 ![log_err](https://us1.discourse-cdn.com/elastic/original/3X/e/e/ee5626fde82bd0c7c2fea0236ff5b9a7dcd2feae.png)

```auto
Any help you can provide is greatly appreciated.  

Thank you.
```

---

<div class="post-metadata">

**Author:** ![MKirby](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Post date:** [October 7, 2021, 5:27pm UTC](https://discuss.elastic.co/t/finding-data-with-logstash-7-13-4/286135/4 "2021-10-07T17:27:13Z")

</div>

It is corrected. No more errors.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 10, 2021, 10:45pm UTC](https://discuss.elastic.co/t/finding-data-with-logstash-7-13-4/286135/5 "2021-10-10T22:45:49Z")

</div>

Just a few things for future topics @MKirby;

- Please don't post pictures of text or code. They are difficult to read, impossible to search and replicate (if it's code), and some people may not be even able to see them
- Please also format your code/logs/config using the `</>` button, or markdown style back ticks. It helps to make things easy to read which helps us help you

And if you've found a solution then it'd be good to share it in the thread, it might help someone in future.

---

<div class="post-metadata">

**Author:** ![MKirby](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MKirby](https://discuss.elastic.co/u/MKirby)\
**Post date:** [October 12, 2021, 3:02pm UTC](https://discuss.elastic.co/t/finding-data-with-logstash-7-13-4/286135/6 "2021-10-12T15:02:58Z")

</div>

My bad on the picture. Not something I do regularly, you can check other posts.

In the end the error was being displayed due to the positioning of my code. I had the output of the syslog placed above the output for the Beats. This was causing my troubles. When I moved the syscode output down below the Beats output it worked.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 12, 2021, 8:44pm UTC](https://discuss.elastic.co/t/finding-data-with-logstash-7-13-4/286135/7 "2021-10-12T20:44:15Z")

</div>

No worries, and thanks for sharing that solution 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 9, 2021, 8:45pm UTC](https://discuss.elastic.co/t/finding-data-with-logstash-7-13-4/286135/8 "2021-11-09T20:45:13Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
