# Forward logs from Kiwi to Elasticsearch

**URL:** <https://discuss.elastic.co/t/forward-logs-from-kiwi-to-elasticsearch/247682>\
**Category:** Logstash\
**Created:** [September 6, 2020, 4:32pm UTC](https://discuss.elastic.co/t/forward-logs-from-kiwi-to-elasticsearch/247682 "2020-09-06T16:32:03Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![markb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markb/32/53487_2.png) [@markb](https://discuss.elastic.co/u/markb)\
**Post date:** [September 6, 2020, 4:32pm UTC](https://discuss.elastic.co/t/forward-logs-from-kiwi-to-elasticsearch/247682/1 "2020-09-06T16:32:03Z")

</div>

I would like to forward logs from Kiwi Syslog Server to Elasticsearch by Logstash.  
After configuring both Kiwi log action and Logstash pipeline I see no log in ES side.

This is the Kiwi remote host forward rule:

 ![Screen Shot 2020-09-06 at 19.26.27](https://us1.discourse-cdn.com/elastic/original/3X/d/1/d17f9bbe218fd6ffe441963d9ecac20054b97ef2.png)

This is a Logstash pipeline:

```auto
    input {
        udp {
            port => 514
            type => "syslog"
        }
    }
    filter {
    }
    output {
        if [type] == "syslog" {
            elasticsearch {
                hosts => ["https://xxx.eu-west-1.aws.found.io:9243"]
                user => "elastic"
                password => "xxx"
                index => "logs-endpoint-syslog-%{+YYYY.MM.dd}"
            }
        }
    }

```

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [September 6, 2020, 9:28pm UTC](https://discuss.elastic.co/t/forward-logs-from-kiwi-to-elasticsearch/247682/2 "2020-09-06T21:28:32Z")

</div>

What's in the Logstash logs?  
Have you tried adding a `stdout` in the output to see if there's anything happening?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 7, 2020, 2:16am UTC](https://discuss.elastic.co/t/forward-logs-from-kiwi-to-elasticsearch/247682/3 "2020-09-07T02:16:23Z")

</div>

Where and how are you running Logstash?

If it is a Linux system, the port `514` could be already been used by a local rsyslog server, and even if it is not the case, this is a privileged port, logstash won't be able to bind to that port unless you are running it as `root`, which is not the case if you are running Logstash as a service.

---

<div class="post-metadata">

**Author:** ![markb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markb/32/53487_2.png) [@markb](https://discuss.elastic.co/u/markb)\
**Post date:** [September 7, 2020, 8:33am UTC](https://discuss.elastic.co/t/forward-logs-from-kiwi-to-elasticsearch/247682/4 "2020-09-07T08:33:41Z")

</div>

I tried TCP 5000 and 9243 - the result is the same, no logs arrive.

---

<div class="post-metadata">

**Author:** ![markb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/markb/32/53487_2.png) [@markb](https://discuss.elastic.co/u/markb)\
**Post date:** [September 7, 2020, 8:34am UTC](https://discuss.elastic.co/t/forward-logs-from-kiwi-to-elasticsearch/247682/5 "2020-09-07T08:34:32Z")

</div>

Is it possible to debug it some way? What exactly the "stdout" parameter should look like?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [September 7, 2020, 1:43pm UTC](https://discuss.elastic.co/t/forward-logs-from-kiwi-to-elasticsearch/247682/6 "2020-09-07T13:43:15Z")

</div>

You need to look into the logstash logs to see what is happening.

To use the `stdout` output you just need to add it in the `output` block.

```auto
output {
    stdout { }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 5, 2020, 1:43pm UTC](https://discuss.elastic.co/t/forward-logs-from-kiwi-to-elasticsearch/247682/7 "2020-10-05T13:43:28Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
