# Input Filter: Syslog vs TCP/UDP

**URL:** <https://discuss.elastic.co/t/input-filter-syslog-vs-tcp-udp/135437>\
**Category:** Logstash\
**Created:** [June 11, 2018, 10:44pm UTC](https://discuss.elastic.co/t/input-filter-syslog-vs-tcp-udp/135437 "2018-06-11T22:44:32Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![mrahim](https://avatars.discourse-cdn.com/v4/letter/m/fbc32d/32.png) [@mrahim](https://discuss.elastic.co/u/mrahim)\
**Post date:** [June 11, 2018, 10:44pm UTC](https://discuss.elastic.co/t/input-filter-syslog-vs-tcp-udp/135437/1 "2018-06-11T22:44:32Z")

</div>

Hi, I am looking to create an ELK pipeline for a variety of Syslog messages. While I thought it would make sense to use the Syslog input filter in Logstash, I read this piece about why Syslog might not be the most beneficial: [https://www.kartar.net/2014/09/when-logstash-and-syslog-go-wrong/](https://www.kartar.net/2014/09/when-logstash-and-syslog-go-wrong/)

Thoughts on what is more useful depending on the application?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 11, 2018, 11:56pm UTC](https://discuss.elastic.co/t/input-filter-syslog-vs-tcp-udp/135437/2 "2018-06-11T23:56:28Z")

</div>

It depends on your messages. If the syslog input successfully parses them then it makes sense to use it. If not, it does not. You really need to try it.

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [June 12, 2018, 9:26am UTC](https://discuss.elastic.co/t/input-filter-syslog-vs-tcp-udp/135437/3 "2018-06-12T09:26:26Z")

</div>

In a perfect world the syslog input would be all you need. However the world isn't perfect, and vendors do all kinds of weird stuff with syslog. We maintain a test file of all of the weirdness we have seen, and use it to validate our base syslog parsing.

The grok patterns to handle almost all of the variations come together in a "super pattern" called KOIOSSYSLOGBASEPARSER.

You can see how this works here...

> **[koiossian/synesis\_lite\_syslog](https://github.com/koiossian/synesis_lite_syslog)**
>
> synesis\_lite\_syslog - Syslog collection with Elastic Stack

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 10, 2018, 9:26am UTC](https://discuss.elastic.co/t/input-filter-syslog-vs-tcp-udp/135437/4 "2018-07-10T09:26:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
