# How to configure Logstash and Syslog ng to send and recieve logs?

**URL:** <https://discuss.elastic.co/t/how-to-configure-logstash-and-syslog-ng-to-send-and-recieve-logs/213773>\
**Category:** Logstash\
**Created:** [January 4, 2020, 11:40am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-and-syslog-ng-to-send-and-recieve-logs/213773 "2020-01-04T11:40:38Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Coder\_HK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/coder_hk/32/57814_2.png) [@Coder\_HK](https://discuss.elastic.co/u/Coder_HK)\
**Post date:** [January 4, 2020, 11:40am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-and-syslog-ng-to-send-and-recieve-logs/213773/1 "2020-01-04T11:40:38Z")

</div>

I want to send syslog ng logs to logstash, I have installed security onion as a VM and want to send those logs to logstash which is on Ubuntu (another VM) kindly tell me how to configure both syslog-ng.log and logstash.conf to send and recieve logs.

---

<div class="post-metadata">

**Author:** ![Rob\_wylde](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rob_wylde/32/58231_2.png) [@Rob\_wylde](https://discuss.elastic.co/u/Rob_wylde)\
**Post date:** [January 5, 2020, 3:59am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-and-syslog-ng-to-send-and-recieve-logs/213773/2 "2020-01-05T03:59:28Z")

</div>

> **[How To Centralize Logs with Rsyslog, Logstash, and Elasticsearch on Ubuntu...](https://www.digitalocean.com/community/tutorials/how-to-centralize-logs-with-rsyslog-logstash-and-elasticsearch-on-ubuntu-14-04)**
>
> Rsyslog, Elasticsearch, and Logstash provide the tools to transmit, transform, and store your log data. In this tutorial, you will learn how to create a centralized rsyslog server to store log files from multiple systems and then use Logstash to send

This is the how-to i followed to get things working. I however just setup logstash to listen on a port and format the syslog events with json on the client and send directly to logstash.

FYI asking for help while show no evidence of attempting to solve the issue on your own. Will likely result in very few replies.

---

<div class="post-metadata">

**Author:** ![Coder\_HK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/coder_hk/32/57814_2.png) [@Coder\_HK](https://discuss.elastic.co/u/Coder_HK)\
**Post date:** [January 5, 2020, 7:54am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-and-syslog-ng-to-send-and-recieve-logs/213773/3 "2020-01-05T07:54:53Z")

</div>

That's what my question was. What did you do to setup logstash to listen on a port ?

---

<div class="post-metadata">

**Author:** ![Rob\_wylde](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rob_wylde/32/58231_2.png) [@Rob\_wylde](https://discuss.elastic.co/u/Rob_wylde)\
**Post date:** [January 5, 2020, 8:22am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-and-syslog-ng-to-send-and-recieve-logs/213773/4 "2020-01-05T08:22:55Z")

</div>

I once again suggest you read the documentation in the link provided in my previous because it answers this very question. I'll gladly help further but when replying please include the configuration file that you're having issues with.

---

<div class="post-metadata">

**Author:** ![Coder\_HK](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/coder_hk/32/57814_2.png) [@Coder\_HK](https://discuss.elastic.co/u/Coder_HK)\
**Post date:** [January 5, 2020, 3:14pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-and-syslog-ng-to-send-and-recieve-logs/213773/5 "2020-01-05T15:14:17Z")

</div>

Thank you very much.  
Please read the question carefully before answering. I don't want to repeat but I have to. I have installed Security onion as a VM and ubuntu as another VM. I want to forward SO logs to Ubuntu(logstash)

I have installed filebeat and configured it. I have configured logstash on ubuntu aswell. I am already recieving logs from winlogbeat. Just tell me how to configure FIlebeat on SO to send logs to logstash, which is on ubuntu. thank you ...

---

<div class="post-metadata">

**Author:** ![Rob\_wylde](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rob_wylde/32/58231_2.png) [@Rob\_wylde](https://discuss.elastic.co/u/Rob_wylde)\
**Post date:** [January 5, 2020, 7:20pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-and-syslog-ng-to-send-and-recieve-logs/213773/6 "2020-01-05T19:20:43Z")

</div>

Good luck to you

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 2, 2020, 7:20pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-and-syslog-ng-to-send-and-recieve-logs/213773/7 "2020-02-02T19:20:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
