# How to create logstash-\* index pattern to see syslog messages

**URL:** <https://discuss.elastic.co/t/how-to-create-logstash-index-pattern-to-see-syslog-messages/277705>\
**Category:** Kibana\
**Created:** [July 3, 2021, 10:06am UTC](https://discuss.elastic.co/t/how-to-create-logstash-index-pattern-to-see-syslog-messages/277705 "2021-07-03T10:06:40Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ankan1979](https://avatars.discourse-cdn.com/v4/letter/a/d9b06d/32.png) [@ankan1979](https://discuss.elastic.co/u/ankan1979)\
**Post date:** [July 3, 2021, 10:06am UTC](https://discuss.elastic.co/t/how-to-create-logstash-index-pattern-to-see-syslog-messages/277705/1 "2021-07-03T10:06:41Z")

</div>

Hi,

I am very new to ILK stack. I am forwarding syslog messages from my routers and switches to Logstash and want to see those in Kibana. When I am trying to add index pattern named logstash-\* from Kibana portal it's not showing any index named with the logstash-\*. Can anyone help me to resolve this issue. My logstash file config is given below:

#Specify listening port for incoming logs from the beats

input {  
beats {  
port =\> 5044  
}  
}

# Used to parse syslog messages and send it to Elasticsearch for storing

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGLINE}" }  
}  
date {  
match =\> ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

# Specify an Elastisearch instance

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 6, 2021, 1:45am UTC](https://discuss.elastic.co/t/how-to-create-logstash-index-pattern-to-see-syslog-messages/277705/2 "2021-07-06T01:45:27Z")

</div>

Welcome to our community! 😃

> [@ankan1979](#):
>
> index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"

This will be creating index names based on the Beat that is sending the data. You can check this by using the `_cat/indices?v` API and see what indexes live in Elasticsearch.

---

<div class="post-metadata">

**Author:** ![ankan1979](https://avatars.discourse-cdn.com/v4/letter/a/d9b06d/32.png) [@ankan1979](https://discuss.elastic.co/u/ankan1979)\
**Post date:** [July 7, 2021, 5:56am UTC](https://discuss.elastic.co/t/how-to-create-logstash-index-pattern-to-see-syslog-messages/277705/3 "2021-07-07T05:56:07Z")

</div>

Thanks for your reply. Can you please let me know the procedure to create index pattern for syslog. From the above logstash configuration I am forwarding syslog to port 5044 and I want to see those logs in Kibana portal. After lots of searching I found that I need to create index pattern named logstash-\* to see the syslog messages. But I can't found any pattern named logstash-\*. Please help me to resolve this issue.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 4, 2021, 5:56am UTC](https://discuss.elastic.co/t/how-to-create-logstash-index-pattern-to-see-syslog-messages/277705/4 "2021-08-04T05:56:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
