# How to configure "Logstash" syslog

**URL:** <https://discuss.elastic.co/t/how-to-configure-logstash-syslog/162074>\
**Category:** Logstash\
**Created:** [December 25, 2018, 2:18pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-syslog/162074 "2018-12-25T14:18:23Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![kuckaprozova](https://avatars.discourse-cdn.com/v4/letter/k/2bfe46/32.png) [@kuckaprozova](https://discuss.elastic.co/u/kuckaprozova)\
**Post date:** [December 25, 2018, 2:18pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-syslog/162074/1 "2018-12-25T14:18:24Z")

</div>

I have a question. I started using docker-elk but ı have a problem because Logstash syslog is not working.Actually the default conf file was working.

This using : [https://github.com/deviantony/docker-elk](https://github.com/deviantony/docker-elk)

But I was working this way;

```auto
nc localhost 5000 </var/log/syslog

```

But now I want to work on the logstash.conf file but I can't do it

default logstash.conf

```auto
input {
  tcp {
    port => 5000
  }
}

## Add your filters / logstash plugins configuration here

output {
  elasticsearch {
    hosts => "elasticsearch:9200"
  }
}

```

logstash.conf

```auto
input {
  file {
    path => "/var/log/syslog"
    start_position => "beginning"
    sincedb_path => "/dev/null"
  }
}

output {
 elasticsearch {
   hosts => ["elasticsearch:9200"]
 }
 stdout { codec => rubydebug }
}

```

Why does this conf file not work? How do I run it?

thanks in advance

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 26, 2018, 9:50pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-syslog/162074/2 "2018-12-26T21:50:04Z")

</div>

So... it's the second configuration file that isn't working?

---

<div class="post-metadata">

**Author:** ![kuckaprozova](https://avatars.discourse-cdn.com/v4/letter/k/2bfe46/32.png) [@kuckaprozova](https://discuss.elastic.co/u/kuckaprozova)\
**Post date:** [December 27, 2018, 10:08am UTC](https://discuss.elastic.co/t/how-to-configure-logstash-syslog/162074/3 "2018-12-27T10:08:45Z")

</div>

Yes.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [January 6, 2019, 8:09pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-syslog/162074/4 "2019-01-06T20:09:55Z")

</div>

Does the Logstash process running inside the Docker container have access to the host's /var/log/syslog file? Unless you're mounting e.g. /var/log from the host into the container Logstash will attempt to read /var/log/syslog from the container's file system, which most likely isn't what you want.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2019, 8:09pm UTC](https://discuss.elastic.co/t/how-to-configure-logstash-syslog/162074/5 "2019-02-03T20:09:59Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
