# Getting Data from Syslog into Elasticsearch/Kibana

**URL:** <https://discuss.elastic.co/t/getting-data-from-syslog-into-elasticsearch-kibana/270464>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 17, 2021, 8:33pm UTC](https://discuss.elastic.co/t/getting-data-from-syslog-into-elasticsearch-kibana/270464 "2021-04-17T20:33:48Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![bryonadams](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bryonadams/32/88050_2.png) [@bryonadams](https://discuss.elastic.co/u/bryonadams)\
**Post date:** [April 17, 2021, 8:33pm UTC](https://discuss.elastic.co/t/getting-data-from-syslog-into-elasticsearch-kibana/270464/1 "2021-04-17T20:33:49Z")

</div>

I've just gotten my first Filebeats agent running and sending data into Elasticsearch, though I'm not sure why the messages are so long. I'm guessing everything after this @timestamp field is something from Beats or Elasticsearch? Not sure how to prune that out of the messages when viewing them or if I need to prune something from the Filebeats configuration.

Log message looks like so:

`Apr 17 16:28:17 sfos-xg.ducknet.org device="SFW" date=2021-04-17 time=16:28:17 timezone="EDT" device_name="SFVH" device_id=C01001DJD7TDY26 log_id=063711517815 log_type="Event" log_component="DDNS" log_subtype="System" status="Success" priority=Notice host=xyz.ducknet.org updatedip=my_ip_address reason="N/A" message="DDNS update for host xyz.ducknet.org was Successful. Updated with IP my_ip_address."`

When I see the message in Kibana it looks like:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/6/e/6e9aab6506871c639f0ac9a9fa0bfdc2d887c6aa.png)

Beats is configured as such:  
`/etc/filebeat/filebeat.yml`

```auto
 setup.kibana:
 # Kibana Host
   host: "kibana.ducknet.org:5601"
 # ---------------------------- Elasticsearch Output ----------------------------
 output.elasticsearch:
   # Array of hosts to connect to.
   hosts: ["kibana.ducknet.org:9200"]

```

`/etc/filebeat/modules.d/sophos.yml`

```auto
 - module: sophos
   xg:
     enabled: true
     # known firewalls
     var.known_devices:
       - serial_number: "C01001DJD7TDY26"
         hostname: "sfos-xg.ducknet.org"

    var.paths: /var/log/sfos-xg.ducknet.org/forwarded-logs.log

```

Edit:  
Looks like possibly what I want is just the contents of this message field.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/f/cf5f89fc715c3819a5e5ddc517418165162d5eb8.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2021, 10:34pm UTC](https://discuss.elastic.co/t/getting-data-from-syslog-into-elasticsearch-kibana/270464/2 "2021-05-15T22:34:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
