# How to import syslog data into logstash

**URL:** <https://discuss.elastic.co/t/how-to-import-syslog-data-into-logstash/302521>\
**Category:** Logstash\
**Created:** [April 15, 2022, 8:19pm UTC](https://discuss.elastic.co/t/how-to-import-syslog-data-into-logstash/302521 "2022-04-15T20:19:04Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![trubeat\_elk](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/trubeat_elk/32/104428_2.png) [@trubeat\_elk](https://discuss.elastic.co/u/trubeat_elk)\
**Post date:** [April 15, 2022, 8:19pm UTC](https://discuss.elastic.co/t/how-to-import-syslog-data-into-logstash/302521/1 "2022-04-15T20:19:04Z")

</div>

Hello ,

I am newbie in ELK.This is the first time I am working on ELK .I want to know how to import syslog data into Logtash and then see that data in Kibana.

Sample events looks like below.  
date/time host process PID message  
Dec 5 06:26:01 s-login-01 CRON[1525214]: pam\_unix(cron:session): session opened for user xyz by (uid=0)

Dec 5 06:30:01 s-login-01 cron[1525865]: sendmail: server message: 501 5.1.3 Invalid address

How to write the syslog.conf. and also if I download a log file and upload via UI of Kibana what override settings should I make

path : /project-admin/s-backup/admin/logs/s-login-01/syslog/

Please explain or write in details as I am new to ELK.

Thanks in Advance

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2022, 8:19pm UTC](https://discuss.elastic.co/t/how-to-import-syslog-data-into-logstash/302521/2 "2022-05-13T20:19:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
