# JSON and syslog in LogStash — how to handle them both?

**URL:** <https://discuss.elastic.co/t/json-and-syslog-in-logstash-how-to-handle-them-both/52172>\
**Category:** Logstash\
**Created:** [June 8, 2016, 8:23am UTC](https://discuss.elastic.co/t/json-and-syslog-in-logstash-how-to-handle-them-both/52172 "2016-06-08T08:23:41Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jojo](https://avatars.discourse-cdn.com/v4/letter/j/ecd19e/32.png) [@jojo](https://discuss.elastic.co/u/jojo)\
**Post date:** [June 8, 2016, 8:23am UTC](https://discuss.elastic.co/t/json-and-syslog-in-logstash-how-to-handle-them-both/52172/1 "2016-06-08T08:23:41Z")

</div>

I send 2 different types of data to Logstash from filebeat: json and syslog. Previously it was only json and it worked fine but now I've added syslog also.

I want to display them both in Kibana in separate dashboards or however it's done. Here's a part of my `/etc/logstash/conf.d/my-logstash.conf` config:

```
    output {
      elasticsearch { hosts => ["localhost:9200"] }
      stdout { codec => json } # if this correct?
    }
    
    filter {

      # if this correct?
      json {
        source => "message"
      }
    
      if [type] == "syslog" {
        grok {
          match => { "message" => "some regexp....." }
          add_field => ["received_at", "%{@timestamp}"]
          add_field => ["received_from", "%{host}"]
        }
        syslog_pri { }
        date {
          match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
        }
      }
    }

```

I'm not sure if it's correct since I send both json and syslog to it. My questions are in the code. Or perhaps there's also something else I've missed?

P.S.

And also, how can I display those 2 formats separately in Kibana, is it done via different dashboards?

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [June 8, 2016, 6:32pm UTC](https://discuss.elastic.co/t/json-and-syslog-in-logstash-how-to-handle-them-both/52172/2 "2016-06-08T18:32:17Z")

</div>

IIRC recent versions of Filebeat support JSON decoding natively. If not you'll want to use a json filter to deal with the JSON data, but only for those events that indeed are JSON. I suggest you set a field to indicate this in your Filebeat prospector, e.g. set the `codec` field to "JSON" and use that in a Logstash conditional:

```plaintext
filter {
  if [codec] == "JSON" {
    json {
      source => "message"
    }
  }
}

```

> And also, how can I display those 2 formats separately in Kibana, is it done via different dashboards?

You don't have to use different visualizations but you could.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:54am UTC](https://discuss.elastic.co/t/json-and-syslog-in-logstash-how-to-handle-them-both/52172/3 "2017-07-06T04:54:05Z")

</div>


