# How to Read logs from Solaris 11.3 SPARC and push to logstash on rhel

**URL:** <https://discuss.elastic.co/t/how-to-read-logs-from-solaris-11-3-sparc-and-push-to-logstash-on-rhel/241358>\
**Category:** Logstash\
**Created:** [July 15, 2020, 8:04pm UTC](https://discuss.elastic.co/t/how-to-read-logs-from-solaris-11-3-sparc-and-push-to-logstash-on-rhel/241358 "2020-07-15T20:04:27Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dhanshake](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dhanshake/32/72200_2.png) [@dhanshake](https://discuss.elastic.co/u/dhanshake)\
**Post date:** [July 15, 2020, 8:04pm UTC](https://discuss.elastic.co/t/how-to-read-logs-from-solaris-11-3-sparc-and-push-to-logstash-on-rhel/241358/1 "2020-07-15T20:04:27Z")

</div>

Hey,

Any alternative to Filebeat which helps in reading application / database logs from Solaris server (Solaris 11.3 SPARC) and push it to my logstash on my rhel ?

P.s filebeat is not supported in Solaris SPARC systems.

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [July 16, 2020, 2:55pm UTC](https://discuss.elastic.co/t/how-to-read-logs-from-solaris-11-3-sparc-and-push-to-logstash-on-rhel/241358/2 "2020-07-16T14:55:58Z")

</div>

First off all, build centralized syslog server in Linux that will received the syslog from Solaris.  
Put the application/database log into the syslog facility, then setup the syslog to forward the log to the centralized syslog that you already created.  
Next, in centralized syslog, install the filebeat and read the logs that you interested.  
You can install centralized syslog as follow:  
[https://www.tecmint.com/create-centralized-log-server-with-rsyslog-in-centos-7/](https://www.tecmint.com/create-centralized-log-server-with-rsyslog-in-centos-7/)

Regards,  
Fadjar Tandabawana

---

<div class="post-metadata">

**Author:** ![dhanshake](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dhanshake/32/72200_2.png) [@dhanshake](https://discuss.elastic.co/u/dhanshake)\
**Post date:** [July 23, 2020, 7:02am UTC](https://discuss.elastic.co/t/how-to-read-logs-from-solaris-11-3-sparc-and-push-to-logstash-on-rhel/241358/3 "2020-07-23T07:02:21Z")

</div>

@fadjar340 thanks for your response.

Other than syslog, any other things ?

Because I'm finding difficulties in parsing multi line messages via syslog.

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [July 23, 2020, 7:54am UTC](https://discuss.elastic.co/t/how-to-read-logs-from-solaris-11-3-sparc-and-push-to-logstash-on-rhel/241358/4 "2020-07-23T07:54:40Z")

</div>

Please read this:

> **[How to collect and manage all of your multi line logs](https://www.datadoghq.com/blog/multiline-logging-guide/#rsyslog)**
>
> Learn how to properly collect your multi-line logs and get the most out of them.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 20, 2020, 7:54am UTC](https://discuss.elastic.co/t/how-to-read-logs-from-solaris-11-3-sparc-and-push-to-logstash-on-rhel/241358/5 "2020-08-20T07:54:52Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
