# How to convert json input to Syslog output

**URL:** <https://discuss.elastic.co/t/how-to-convert-json-input-to-syslog-output/45165>\
**Category:** Logstash\
**Created:** [March 22, 2016, 10:17pm UTC](https://discuss.elastic.co/t/how-to-convert-json-input-to-syslog-output/45165 "2016-03-22T22:17:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![herofish](https://avatars.discourse-cdn.com/v4/letter/h/a9a28c/32.png) [@herofish](https://discuss.elastic.co/u/herofish)\
**Post date:** [March 22, 2016, 10:17pm UTC](https://discuss.elastic.co/t/how-to-convert-json-input-to-syslog-output/45165/1 "2016-03-22T22:17:41Z")

</div>

Hello,

I have a working Logstash server collecting logs from Windows hosts with the nxlog agent (sending json format).

The Logstash server is taking the Windows agent logs and forwarding them to two destinations, and overall it's working fine.

The problem is, one of the destinations (HostA as shown below) does not understand json format, so I would like to have Logstash convert the output for that particular destination to basic Syslog format. I am using the syslog output module, but they are still receiving events in json format and cannot use it.

Any suggestions would be much appreciated.

My configuration is copied below.

input {

# NXLOG input from Windows hosts

tcp {  
port =\> 5140  
}  
}

# Filter

filter{}

# Output to Legacy log collector

output {  
syslog {  
facility =\> local6  
host =\> "HostA"  
port =\> 514  
severity =\> informational  
rfc =\> rfc5424  
}  
}

# Output to new log collector

output {  
lumberjack {  
hosts =\> "HostB"  
port =\> 9010  
ssl\_certificate =\> "/etc/cert.crt"  
codec =\> "json"  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [March 25, 2016, 1:54pm UTC](https://discuss.elastic.co/t/how-to-convert-json-input-to-syslog-output/45165/2 "2016-03-25T13:54:38Z")

</div>

So you're receiving serialized JSON via TCP and you want to ship it via Lumberjack except for HostA where you want to use syslog? The problem is that you're never deserializing the JSON string you receive, so the plaintext message the syslog output sees is a JSON string.

Try using a json codec for your tcp input so that you get the fields inside the JSON object extracted into discrete fields. By default the `message` field will form the message part of the syslog message but you can change that with the syslog output's `message` option.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:05am UTC](https://discuss.elastic.co/t/how-to-convert-json-input-to-syslog-output/45165/3 "2017-07-06T05:05:18Z")

</div>


