# How to use "syslog\_hostname" in Kibana Visualization?

**URL:** <https://discuss.elastic.co/t/how-to-use-syslog-hostname-in-kibana-visualization/86182>\
**Category:** Kibana\
**Created:** [May 17, 2017, 11:47pm UTC](https://discuss.elastic.co/t/how-to-use-syslog-hostname-in-kibana-visualization/86182 "2017-05-17T23:47:28Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Cdnvballer](https://avatars.discourse-cdn.com/v4/letter/c/da6949/32.png) [@Cdnvballer](https://discuss.elastic.co/u/Cdnvballer)\
**Post date:** [May 17, 2017, 11:47pm UTC](https://discuss.elastic.co/t/how-to-use-syslog-hostname-in-kibana-visualization/86182/1 "2017-05-17T23:47:28Z")

</div>

Hi,

I'm very new to ELK ; managed to set up an environment where syslog events are shipped via Filebeat to an ELK server for the actual reporting.... From Kibana --\> Discover, I can see the active syslog events , and can filter to events of interest when specifying "source" along with fields "syslog\_hostname" and "message" . I saved the search... =)

Now, I'd like to create a visualization, i.e. events over time, but using the "syslog\_hostname" to identify the actual sendiers.. as opposed to using Filebeats index "source" which seems to only show the address of the syslog collector... . .. how is this done? I try to specify the saved search, but from there I'm stuck...

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 19, 2017, 8:01pm UTC](https://discuss.elastic.co/t/how-to-use-syslog-hostname-in-kibana-visualization/86182/2 "2017-05-19T20:01:59Z")

</div>

Can you elaborate a bit more on what kind of graph you'd like to create? For instance, are you trying to create a line chart with a separate line for each "syslog\_hostname"?

---

<div class="post-metadata">

**Author:** ![Cdnvballer](https://avatars.discourse-cdn.com/v4/letter/c/da6949/32.png) [@Cdnvballer](https://discuss.elastic.co/u/Cdnvballer)\
**Post date:** [May 20, 2017, 5:01pm UTC](https://discuss.elastic.co/t/how-to-use-syslog-hostname-in-kibana-visualization/86182/3 "2017-05-20T17:01:32Z")

</div>

I'm looking to create a vertical bar chart that tracks the # of events over time.  
From some examples I've seen, Y-axis is count of events, X-Axis would be time, but the bar itself can somehow be split up to show a breakdown on the actual Ip addresses? (using some sort of Sub-aggregation)....

similar to what's shown here, where the bar is divided into multiple IP addresses...

> **[How To Use Kibana Dashboards and Visualizations | DigitalOcean](https://www.digitalocean.com/community/tutorials/how-to-use-kibana-dashboards-and-visualizations)**
>
> The Kibana interface is divided into four sections: Discover, Visualize, Dashboard, and Settings. In this tutorial, we will go over the basics of each section, and demonstrate how each section can be used.

---

<div class="post-metadata">

**Author:** ![Cdnvballer](https://avatars.discourse-cdn.com/v4/letter/c/da6949/32.png) [@Cdnvballer](https://discuss.elastic.co/u/Cdnvballer)\
**Post date:** [May 20, 2017, 5:12pm UTC](https://discuss.elastic.co/t/how-to-use-syslog-hostname-in-kibana-visualization/86182/4 "2017-05-20T17:12:46Z")

</div>

To add,  
I'm using the following for part of my logstash config... thanks

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:sys  
log\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 22, 2017, 3:15pm UTC](https://discuss.elastic.co/t/how-to-use-syslog-hostname-in-kibana-visualization/86182/5 "2017-05-22T15:15:15Z")

</div>

If I'm understanding correctly, I think you'll want to do something like below. Change "clientip" in the terms agg into "syslog\_hostname". Let me know if this isn't quite what you want.

 ![](https://us1.discourse-cdn.com/elastic/original/3X/a/6/a672e30e17ced87ef8ea2b91fb70c66538e28d61.png)

---

<div class="post-metadata">

**Author:** ![Cdnvballer](https://avatars.discourse-cdn.com/v4/letter/c/da6949/32.png) [@Cdnvballer](https://discuss.elastic.co/u/Cdnvballer)\
**Post date:** [May 22, 2017, 5:38pm UTC](https://discuss.elastic.co/t/how-to-use-syslog-hostname-in-kibana-visualization/86182/6 "2017-05-22T17:38:38Z")

</div>

Thanks Matt,

this is exactly what I want to do, but I run into this problem:

using my filebeats input , I can create the initial vertical bar graph and add Date Histogram to the X-Axis.  
when I try to add the Sub aggregation, I can't seem to select or specify "syslog\_hostname" from the list of "Terms"

 ![](https://us1.discourse-cdn.com/elastic/original/3X/d/8/d8f591b0d48b4b878899bdbaaa55485b54b72462.png)

---

<div class="post-metadata">

**Author:** ![Bargs](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/bargs/32/5429_2.png) [@Bargs](https://discuss.elastic.co/u/Bargs)\
**Post date:** [May 22, 2017, 6:01pm UTC](https://discuss.elastic.co/t/how-to-use-syslog-hostname-in-kibana-visualization/86182/7 "2017-05-22T18:01:45Z")

</div>

Does `syslog_hostname` show up in the list of fields on the index pattern management screen (example below)? If not, could you try refreshing the field list by clicking on the Refresh icon on the same page?

 ![](https://us1.discourse-cdn.com/elastic/original/3X/8/8/88dbfe8f491379acea8a0ebec42e23cb4ad5cb59.png)

---

<div class="post-metadata">

**Author:** ![Cdnvballer](https://avatars.discourse-cdn.com/v4/letter/c/da6949/32.png) [@Cdnvballer](https://discuss.elastic.co/u/Cdnvballer)\
**Post date:** [May 22, 2017, 6:33pm UTC](https://discuss.elastic.co/t/how-to-use-syslog-hostname-in-kibana-visualization/86182/8 "2017-05-22T18:33:07Z")

</div>

Thanks!  
this was exactly what was needed -- after refreshing that list, I was able to select the term from the drop-down list

Much Appreciated!!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 19, 2017, 6:33pm UTC](https://discuss.elastic.co/t/how-to-use-syslog-hostname-in-kibana-visualization/86182/9 "2017-06-19T18:33:09Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
