# Gathering logs through Rsyslog/Redis \> Logstash

**URL:** <https://discuss.elastic.co/t/gathering-logs-through-rsyslog-redis-logstash/48277>\
**Category:** Logstash\
**Created:** [April 25, 2016, 7:15am UTC](https://discuss.elastic.co/t/gathering-logs-through-rsyslog-redis-logstash/48277 "2016-04-25T07:15:28Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![brayndasilva](https://avatars.discourse-cdn.com/v4/letter/b/2bfe46/32.png) [@brayndasilva](https://discuss.elastic.co/u/brayndasilva)\
**Post date:** [April 25, 2016, 7:15am UTC](https://discuss.elastic.co/t/gathering-logs-through-rsyslog-redis-logstash/48277/1 "2016-04-25T07:15:28Z")

</div>

Hi,

I'm going to be deploying an ELK stack on a small to medium network very soon and have got my documentation and such all ready to go, but I was wondering about one thing.

I will be capturing Syslogs from routers/switches and NETFlow from specific devices which means that for the Syslogs it will be using UDP port 514. This is a privileged port and Logstash can not listen to it directly unless ran as root.

I have been looking at a few solutions regarding it and found out that with Rsyslog and Redir you can send all files from whatever port to there and it will redirect it with a higher port number to Logstash. Does anyone have experience with this?

Ubuntu Servers 14.04

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:00am UTC](https://discuss.elastic.co/t/gathering-logs-through-rsyslog-redis-logstash/48277/2 "2017-07-06T05:00:49Z")

</div>


