# How to keep syslog header when saving to file?

**URL:** <https://discuss.elastic.co/t/how-to-keep-syslog-header-when-saving-to-file/194130>\
**Category:** Logstash\
**Created:** [August 7, 2019, 3:24am UTC](https://discuss.elastic.co/t/how-to-keep-syslog-header-when-saving-to-file/194130 "2019-08-07T03:24:21Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![dickens88](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dickens88/32/52425_2.png) [@dickens88](https://discuss.elastic.co/u/dickens88)\
**Post date:** [August 7, 2019, 3:24am UTC](https://discuss.elastic.co/t/how-to-keep-syslog-header-when-saving-to-file/194130/1 "2019-08-07T03:24:22Z")

</div>

Guys, when I use logstash to input syslog and keep the message to file, I found it seems logstash won't keep syslog header.

my configuration looks like this:

```auto
input{
     syslog {
        port => 1522
     }
}
output{
    file {
        path => "/log/proxy/%{+yyyyMMdd}/%{host}/%{+HH}.log"
        codec => line { format => "%{message}" }
    }
}

```

and the raw data I captured via tcpdump looks like this:

```auto
.......... <30>Aug 7 08:47:12 blrmwg01 mwg: CEF:0|McAfee|Web Gateway|7.7.2.5.0|200|Proxy-Enable Web Cache|2|rt=Aug 07 2019 08:47:12 cat=Access Log dst=x ...

```

but when I checked the message from file, it looks like this:

```auto
CEF:0|McAfee|Web Gateway|7.7.2.5.0|200|Proxy-Enable Web Cache|2|rt=Aug 07 2019 08:47:12 cat=Access Log dst=x ...

```

in brief, the syslog header is missing. So is it possible to keep the syslog header and save the whole message to file?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 7, 2019, 10:34am UTC](https://discuss.elastic.co/t/how-to-keep-syslog-header-when-saving-to-file/194130/2 "2019-08-07T10:34:03Z")

</div>

By [default](https://github.com/logstash-plugins/logstash-input-syslog/blob/299f9354d2ab9d4c519d2b3b1463002b4b5d95f0/lib/logstash/inputs/syslog.rb#L45) the syslog input uses a grok pattern that parses the priority, timestamp, host, facility, etc. You could override the grok\_pattern option with a pattern that just captures the entire message.

---

<div class="post-metadata">

**Author:** ![dickens88](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dickens88/32/52425_2.png) [@dickens88](https://discuss.elastic.co/u/dickens88)\
**Post date:** [August 7, 2019, 11:15am UTC](https://discuss.elastic.co/t/how-to-keep-syslog-header-when-saving-to-file/194130/3 "2019-08-07T11:15:42Z")

</div>

@Badger  
Thank you for your reply. I'm new in logstash, so i'm not sure how to try your suggestion. I tried to add this configuration in logstash.conf, but it doesn't work.

```auto
filter {
    grok {
        match => { "message" => "%{GREEDYDATA:message}" }
    }
}

```

could you pls kindly note the details.tks

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 7, 2019, 11:19am UTC](https://discuss.elastic.co/t/how-to-keep-syslog-header-when-saving-to-file/194130/4 "2019-08-07T11:19:12Z")

</div>

Not a grok filter, but the [grok\_pattern](https://www.elastic.co/guide/en/logstash/current/plugins-inputs-syslog.html#plugins-inputs-syslog-grok_pattern) option on the filter. Note the warning there about parsing the timestamp. You will have to add a grok that gets the timestamp out of the message (you can use the same grok pattern that the syslog filter defaults to) and remove the tag that the syslog filter adds.

---

<div class="post-metadata">

**Author:** ![dickens88](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dickens88/32/52425_2.png) [@dickens88](https://discuss.elastic.co/u/dickens88)\
**Post date:** [August 7, 2019, 11:52am UTC](https://discuss.elastic.co/t/how-to-keep-syslog-header-when-saving-to-file/194130/5 "2019-08-07T11:52:13Z")

</div>

@Badger  
Accroding to your suggestion, I update my configuration to this. It works then, although I don't know if it is grace... Thank you so much Badger.

```auto
input{
     syslog {
        port => 1522
        grok_pattern => "%{GREEDYDATA:message}"
     }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2019, 11:52am UTC](https://discuss.elastic.co/t/how-to-keep-syslog-header-when-saving-to-file/194130/6 "2019-09-04T11:52:17Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
