How to recognize and separate different syslogs



I have couple of applications sending logs on to logstash on same port using rsyslog.
Is it possible to identify them on logstash syslog input using $InputFileTag or any other tags that I can configure on rsyslog configs ?



$InputFileName /var/log/ceph/ceph-osd.log
$InputFileTag cephlog
$InputFileFacility local0


input {
syslog {
host => ""
port => 1544
if [InputFileTag] =~ "cephlog"{
type => "ceph"
filter {
if [type] =~ "ceph" {
mutate {
add_field => { "environment" => "lab" }

any other way of doing it ?

(Magnus B├Ąck) #2

What happens with the $InputFileTag setting? How (if at all) is that value included in the payload sent over the wire to Logstash? I suggest you use a stdout { codec => rubydebug } output to dump the raw event received by Logstash. Once we know what's available we can talk about how to use that information.

(system) #3

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.