# Get message information from filebeat

**URL:** <https://discuss.elastic.co/t/get-message-information-from-filebeat/244948>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [August 13, 2020, 9:14pm UTC](https://discuss.elastic.co/t/get-message-information-from-filebeat/244948 "2020-08-13T21:14:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![jorge\_rivera](https://avatars.discourse-cdn.com/v4/letter/j/bb73d2/32.png) [@jorge\_rivera](https://discuss.elastic.co/u/jorge_rivera)\
**Post date:** [August 13, 2020, 9:14pm UTC](https://discuss.elastic.co/t/get-message-information-from-filebeat/244948/1 "2020-08-13T21:14:44Z")

</div>

Good afternoon.  
I am starting in ELK issues and I have a question that I hope you will help me solve.

I am sending logs from a cisco 5520 controller to a server (udp: 514) but when I receive the log with filebeat I get the following error

"  
ago 13 16:05:16 srvsyslog filebeat[25982]: 2020-08-13T16:05:16.519-0500 ERROR [syslog] syslog/input.go:243 can't parse event as syslog rfc3164 {"message": "\<46\>MX\_CWLC\_MAN\_FIN: \*rsyncmgrXferTrasport: Aug 13 16:03:20.622: %LOG-6-Q\_IND: [SS]dtl\_arp.c:1544 Unable to add an ARP entry for 81.4.111.10 to the operating system "

I can receive it in kibana but I don't know how to extract the information from the message, I tried the cisco module but it is the same

any ideas how to separate the message with filebeat?

 ![log wlc](https://us1.discourse-cdn.com/elastic/original/3X/3/6/362f30e39810d92ad21c756204b107a87a861a54.jpeg)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 10, 2020, 9:14pm UTC](https://discuss.elastic.co/t/get-message-information-from-filebeat/244948/2 "2020-09-10T21:14:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
