# How to configure syslog (input) in logstash conf file

**URL:** <https://discuss.elastic.co/t/how-to-configure-syslog-input-in-logstash-conf-file/277349>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [June 29, 2021, 12:08pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-input-in-logstash-conf-file/277349 "2021-06-29T12:08:52Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![MdRashid](https://avatars.discourse-cdn.com/v4/letter/m/839c29/32.png) [@MdRashid](https://discuss.elastic.co/u/MdRashid)\
**Post date:** [June 29, 2021, 12:08pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-input-in-logstash-conf-file/277349/1 "2021-06-29T12:08:53Z")

</div>

Hi All,

Im new to ELK i have config ELK in ubuntu as a docker container when i check kibana URL No Elasticsearch indices match your pattern.

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/e/1eaf6e3d40bdf528e4f6e14c148f7b5395eb19a1.png)

Note: - My VM is store in google cloud

Here is my logstash.conf file

```auto
input {
        tcp {
                port => 5044
# syslog_field => "syslog"
# path => /var/log/syslog      
                type => syslog  
                codec => "json"
        }
}

## Add your filters / logstash plugins configuration here

output {
        elasticsearch {
                hosts => "elasticsearch:9200"
                user => "xxxx"
                password => "xxxxxx"
        }
# stdout { codec => rubydebug }
}

```

I dont know to write logstash.conf as input . Please help me out

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [June 29, 2021, 12:19pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-input-in-logstash-conf-file/277349/2 "2021-06-29T12:19:43Z")

</div>

Your elasticsearch output section needs to specify the target index. Look in Kibana index management or monitoring, there may be an index "logstash\*" or some other default name.

---

<div class="post-metadata">

**Author:** ![MdRashid](https://avatars.discourse-cdn.com/v4/letter/m/839c29/32.png) [@MdRashid](https://discuss.elastic.co/u/MdRashid)\
**Post date:** [June 29, 2021, 2:29pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-input-in-logstash-conf-file/277349/3 "2021-06-29T14:29:48Z")

</div>

can u send me any link related to question or any example ...im looking in google but didnt getting it

---

<div class="post-metadata">

**Author:** ![MdRashid](https://avatars.discourse-cdn.com/v4/letter/m/839c29/32.png) [@MdRashid](https://discuss.elastic.co/u/MdRashid)\
**Post date:** [June 29, 2021, 2:50pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-input-in-logstash-conf-file/277349/4 "2021-06-29T14:50:27Z")

</div>

i look in kibana but didnt find any logstash name or any default name

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [June 29, 2021, 3:33pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-input-in-logstash-conf-file/277349/5 "2021-06-29T15:33:58Z")

</div>

This [link](https://www.elastic.co/blog/a-practical-introduction-to-logstash):

```auto
elasticsearch {
 hosts => ["localhost:9200"]
 index => "squid-%{+YYYY.MM.dd}" 
 manage_template => true
 template => "/home/logstash/squid_mapping.json"
 template_name => "squid_template"
}

```

Change the index name to fit yours. You should be getting logstash errors if logstash is receiving data but not sending it.

---

<div class="post-metadata">

**Author:** ![MdRashid](https://avatars.discourse-cdn.com/v4/letter/m/839c29/32.png) [@MdRashid](https://discuss.elastic.co/u/MdRashid)\
**Post date:** [June 29, 2021, 4:43pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-input-in-logstash-conf-file/277349/6 "2021-06-29T16:43:34Z")

</div>

thats output section i want input section first to be work in logstash.conf file

---

<div class="post-metadata">

**Author:** ![rugenl](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rugenl/32/12887_2.png) [@rugenl](https://discuss.elastic.co/u/rugenl)\
**Post date:** [June 29, 2021, 9:16pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-input-in-logstash-conf-file/277349/7 "2021-06-29T21:16:51Z")

</div>

[[Remote syslog to Logstash – Halon](https://support.halon.io/hc/en-us/articles/360000700065-Remote-syslog-to-Logstash)]([https://syslog](https://syslog) input example)

If you use a low port, logstash will have to have privileges.

---

<div class="post-metadata">

**Author:** ![Andre\_Letterer](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andre_letterer/32/42248_2.png) [@Andre\_Letterer](https://discuss.elastic.co/u/Andre_Letterer)\
**Post date:** [June 29, 2021, 10:26pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-input-in-logstash-conf-file/277349/8 "2021-06-29T22:26:30Z")

</div>

Hi folks,

Why not rely on the actual logstash documentation page?  
That should basically help to answer all your questions.

> **[Syslog input plugin | Logstash Reference \[7.13\] | Elastic](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-syslog.html)**

Best

André :elasticheart:

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 27, 2021, 10:26pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-input-in-logstash-conf-file/277349/9 "2021-07-27T22:26:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
