# How to use custom grok pattern for syslog input

**URL:** <https://discuss.elastic.co/t/how-to-use-custom-grok-pattern-for-syslog-input/231494>\
**Category:** Logstash\
**Created:** [May 7, 2020, 9:06am UTC](https://discuss.elastic.co/t/how-to-use-custom-grok-pattern-for-syslog-input/231494 "2020-05-07T09:06:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Hari\_Krishna](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/hari_krishna/32/62678_2.png) [@Hari\_Krishna](https://discuss.elastic.co/u/Hari_Krishna)\
**Post date:** [May 7, 2020, 9:06am UTC](https://discuss.elastic.co/t/how-to-use-custom-grok-pattern-for-syslog-input/231494/1 "2020-05-07T09:06:05Z")

</div>

Hi,

I listening to the port 31230 to get syslogs from a router. The logs are coming in but it doesnt use my grok filter. Kibana uses some default index pattern for syslogs.

```
input {
syslog {
            type => "syslog"
            port => 31230
          }
}
filter {

grok
{
        break_on_match => false
        pattern_definitions => { "mssg" => "((Msg|message|Message|message1|message2|Message1|Message2) [=])"
                                 "nhchg" => "%{WORD} -> %{WORD}"
                                 "debug" => "NDP-DBG"
                                }
        match => {
                "message" => ["%{TIMESTAMP_ISO8601:timestamp} %{WORD:node}:%{WORD:program}:%{INT:pid} %{WORD:tracetype}.*%{mssg} \"%{GREEDYDATA:Message}\""]
                "Message" => ["%{debug:NDPdebug}:%{DATA:function}:%{INT:line}:: %{GREEDYDATA:msg}", "NexthopId %{WORD:nexthop_id}", "state %{WORD:state}", "event %{WORD:event}", "Prefix %{DATA:prefix}/", "NhType_change %{nhchg:nhtype_change}"]
    }
  }
}

```

There is no error in the configuration. I have tried running it by getting input from a file.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 4, 2020, 9:06am UTC](https://discuss.elastic.co/t/how-to-use-custom-grok-pattern-for-syslog-input/231494/2 "2020-06-04T09:06:05Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
