# How to configure syslog output in winlogbeat

**URL:** <https://discuss.elastic.co/t/how-to-configure-syslog-output-in-winlogbeat/137490>\
**Category:** Beats\
**Tags:** winlogbeat\
**Created:** [June 26, 2018, 6:08pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-output-in-winlogbeat/137490 "2018-06-26T18:08:28Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Nickname\_Yu](https://avatars.discourse-cdn.com/v4/letter/n/67e7ee/32.png) [@Nickname\_Yu](https://discuss.elastic.co/u/Nickname_Yu)\
**Post date:** [June 26, 2018, 6:08pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-output-in-winlogbeat/137490/1 "2018-06-26T18:08:28Z")

</div>

In the documentation [https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-logging.html](https://www.elastic.co/guide/en/beats/winlogbeat/current/configuration-logging.html)  
there is a configuration option:  
logging.to\_syslog  
When true, writes all logging output to the syslog.

while there isn't a description about how to configure the output destination address and port. Any one can show me how?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [June 26, 2018, 6:46pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-output-in-winlogbeat/137490/2 "2018-06-26T18:46:09Z")

</div>

I've followed the code path of the `to_syslog` option and this feature should only work under unix system, if you use that under windows you should see the following error in your log.

```auto
syslog is not supported on this OS

```

I will create an issue to remove that documentation in windows.

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [June 26, 2018, 6:47pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-output-in-winlogbeat/137490/3 "2018-06-26T18:47:48Z")

</div>

In your case I think you might want to use the 'to\_eventlog' option to send events to the events log.

---

<div class="post-metadata">

**Author:** ![Nickname\_Yu](https://avatars.discourse-cdn.com/v4/letter/n/67e7ee/32.png) [@Nickname\_Yu](https://discuss.elastic.co/u/Nickname_Yu)\
**Post date:** [June 26, 2018, 6:49pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-output-in-winlogbeat/137490/4 "2018-06-26T18:49:55Z")

</div>

I'm looking for options to send log to syslog. Any idea? I overheard some kind of output plugin. Is that possible?

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [June 26, 2018, 6:54pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-output-in-winlogbeat/137490/5 "2018-06-26T18:54:24Z")

</div>

@Nickname_Yu The option you were referring was to send Winlogbeat own logs to Syslog. It that the goal you were trying to achieve OR you want to send all the events read from Winlogbeat to a Syslog server?

---

<div class="post-metadata">

**Author:** ![Nickname\_Yu](https://avatars.discourse-cdn.com/v4/letter/n/67e7ee/32.png) [@Nickname\_Yu](https://discuss.elastic.co/u/Nickname_Yu)\
**Post date:** [June 26, 2018, 7:00pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-output-in-winlogbeat/137490/6 "2018-06-26T19:00:18Z")

</div>

I want to send all the logs to syslog

---

<div class="post-metadata">

**Author:** ![pierhugues](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/pierhugues/32/48383_2.png) [@pierhugues](https://discuss.elastic.co/u/pierhugues)\
**Post date:** [June 26, 2018, 7:08pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-output-in-winlogbeat/137490/7 "2018-06-26T19:08:51Z")

</div>

@Nickname_Yu currently Winlogbeat or any beats don't have any direct output to Syslog, we support the following outputs:

- Elasticsearch
- Logstash
- Kafka
- Redis

If you really want to send all your events to syslog, I think you have the following options:

- Write a custom Syslog output for beats using our framewok (Syslog is a UDP or TCP connection a string format)
- Use Logstash as an aggregator with the _logstash-output-tcp_ to send events to Syslog.
- If you are not using or planning to use Elasticsearch as a backend, maybe NXLog would solve your problem.

---

<div class="post-metadata">

**Author:** ![Nickname\_Yu](https://avatars.discourse-cdn.com/v4/letter/n/67e7ee/32.png) [@Nickname\_Yu](https://discuss.elastic.co/u/Nickname_Yu)\
**Post date:** [June 26, 2018, 7:18pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-output-in-winlogbeat/137490/8 "2018-06-26T19:18:50Z")

</div>

thanks @pierhugues

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2018, 7:19pm UTC](https://discuss.elastic.co/t/how-to-configure-syslog-output-in-winlogbeat/137490/9 "2018-07-24T19:19:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
