# Kibana unable to parse syslog logs

**URL:** <https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972>\
**Category:** Kibana\
**Created:** [April 27, 2023, 2:39pm UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972 "2023-04-27T14:39:02Z")\
**Posts on this page:** 11\
**Page:** 1

<div class="post-metadata">

**Author:** ![ishan.abhinit](https://avatars.discourse-cdn.com/v4/letter/i/d07c76/32.png) [@ishan.abhinit](https://discuss.elastic.co/u/ishan.abhinit)\
**Post date:** [April 27, 2023, 2:39pm UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972/1 "2023-04-27T14:39:02Z")

</div>

I have a text file which contains data in the below format (syslog).

```auto
Oct 9 2019 23:39:37 myrtle sshd[41925]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.49.202.135 user=root
Oct 9 2019 23:39:37 myrtle sshd[41925]: Failed password for root from 221.49.202.135 port 1930 ssh2
Oct 9 2019 23:39:38 myrtle sshd[41927]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.49.202.135 user=root
Oct 9 2019 23:39:38 myrtle sshd[41927]: Failed password for root from 221.49.202.135 port 55212 ssh2
Oct 10 2019 04:28:55 myrtle sshd[41931]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=108.150.44.62 user=root
Oct 10 2019 04:28:55 myrtle sshd[41931]: Failed password for root from 108.150.44.62 port 17735 ssh2
Oct 10 2019 04:28:56 myrtle sshd[41936]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=108.150.44.62 user=root
Oct 10 2019 04:28:56 myrtle sshd[41936]: Failed password for root from 108.150.44.62 port 54304 ssh2
Oct 10 2019 04:28:57 myrtle sshd[41939]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=108.150.44.62 user=root
Oct 10 2019 04:28:57 myrtle sshd[41939]: Failed password for root from 108.150.44.62 port 33925 ssh2
Oct 10 2019 04:28:58 myrtle sshd[41941]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=108.150.44.62 user=root

```

I am trying to get this parsed on Kibana by uploading a file through Kibana interface. I keep getting the error that "File structure cannot be determined". I tried these override settings:

Number of line to sample: 1000  
Data Format: delimited  
Delimiter: space  
Quote character: not applicable  
Timestamp format: MMM dd yyyy HH:mm:ss

NOTE: This worked in my older Kibana setup which was similar to this current one

Please assist.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 27, 2023, 6:33pm UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972/2 "2023-04-27T18:33:52Z")

</div>

What version are you on?

I just tried on 8.7.0 and it loaded without setting anything... and it picked up the data correctly and parsed out the IP and put the rest in a `message` field

 ![Screenshot 2023-04-27 at 11.43.45 AM](https://us1.discourse-cdn.com/elastic/original/3X/b/b/bbdd4f6c9127423a0c75b07bf0fae24c5f9a0d59.jpeg)

---

<div class="post-metadata">

**Author:** ![ishan.abhinit](https://avatars.discourse-cdn.com/v4/letter/i/d07c76/32.png) [@ishan.abhinit](https://discuss.elastic.co/u/ishan.abhinit)\
**Post date:** [April 28, 2023, 12:16am UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972/3 "2023-04-28T00:16:02Z")

</div>

Exactly, it worked on my previous installation of Kibana. I installed Kibana from [here](https://www.elastic.co/guide/en/kibana/current/rpm.html) from RPM repository.

The Elasticsearch version is 8.7.0. Did I do something wrong this time?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 28, 2023, 1:43am UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972/4 "2023-04-28T01:43:31Z")

</div>

I don't know. I literally used your log lines and they parsed and ended up in Kibana using the system module.

Those are your log lines. I just put them in the file. Pointed the system module at it.

Made sure I ran setup .... Did you run set up?

`filebeat setup -e`

Then ran filebeat and those are the results I posted.

I didn't make any other changes

---

<div class="post-metadata">

**Author:** ![ishan.abhinit](https://avatars.discourse-cdn.com/v4/letter/i/d07c76/32.png) [@ishan.abhinit](https://discuss.elastic.co/u/ishan.abhinit)\
**Post date:** [April 28, 2023, 2:15am UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972/5 "2023-04-28T02:15:01Z")

</div>

I am trying to parse this using Kibana user interface though.

I even tried to parse it using the Filebeat system module. Weird thing is - I have another log file (apache log file which I am parsing using apache module) and I am able to see all the apache log files in Kibana. Its just this syslog file is not showing up in the Kibana. Both the files haves same date ranges.

I had first setup apache files, then ran filebeat setup -e  
Then I updated system modules, and again ran filebeat setup -e.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 28, 2023, 2:28am UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972/6 "2023-04-28T02:28:56Z")

</div>

> [@ishan.abhinit](#):
>
> m trying to parse this using Kibana user interface though.

Ohh sorry I am answering toooo many...

I loaded that through the Upload File in Kibana 8.7.0 All Defaults

As you asked ... I did not set any delimeters etc..etc..

Apache won't work those are not apache logs

There are different parsers...

What I showed above I did with the File Uploader

You are doing something basic wrong.. 🙂

Did you clean out the index / delete the index and try to use Upload All Defaults New Index?

---

<div class="post-metadata">

**Author:** ![ishan.abhinit](https://avatars.discourse-cdn.com/v4/letter/i/d07c76/32.png) [@ishan.abhinit](https://discuss.elastic.co/u/ishan.abhinit)\
**Post date:** [April 28, 2023, 2:48am UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972/7 "2023-04-28T02:48:19Z")

</div>

I too did the same. Loaded them through the Upload File in Kibana with defaults. When default settings did not parse it, then I tried to set delimiters.

Apache logs are working perfectly in Kibana. Kibana is no able to parse system logs.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [April 28, 2023, 4:38am UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972/8 "2023-04-28T04:38:14Z")

</div>

Hmmm

Step by Step

 ![Screenshot 2023-04-27 at 9.00.57 PM](https://us1.discourse-cdn.com/elastic/original/3X/7/9/79d2367538526b0832f57f80d14cad5dc9728a90.png)

File Uploader

 ![Screenshot 2023-04-27 at 9.01.12 PM](https://us1.discourse-cdn.com/elastic/original/3X/b/9/b960f2304fd03e99019fee325691d60e83449021.png)

Contents of file

```auto
$ cat syslog.log
Oct 9 2019 23:39:37 myrtle sshd[41925]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.49.202.135 user=root
Oct 9 2019 23:39:37 myrtle sshd[41925]: Failed password for root from 221.49.202.135 port 1930 ssh2
Oct 9 2019 23:39:38 myrtle sshd[41927]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=221.49.202.135 user=root
Oct 9 2019 23:39:38 myrtle sshd[41927]: Failed password for root from 221.49.202.135 port 55212 ssh2
Oct 10 2019 04:28:55 myrtle sshd[41931]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=108.150.44.62 user=root
Oct 10 2019 04:28:55 myrtle sshd[41931]: Failed password for root from 108.150.44.62 port 17735 ssh2
Oct 10 2019 04:28:56 myrtle sshd[41936]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=108.150.44.62 user=root
Oct 10 2019 04:28:56 myrtle sshd[41936]: Failed password for root from 108.150.44.62 port 54304 ssh2
Oct 10 2019 04:28:57 myrtle sshd[41939]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=108.150.44.62 user=root
Oct 10 2019 04:28:57 myrtle sshd[41939]: Failed password for root from 108.150.44.62 port 33925 ssh2
Oct 10 2019 04:28:58 myrtle sshd[41941]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=108.150.44.62 user=root

```

Load the File: No Special Settings

 ![Screenshot 2023-04-27 at 9.02.18 PM](https://us1.discourse-cdn.com/elastic/original/3X/1/6/16e64a072238f913554d00d111eabf6279d206ce.jpeg)

 ![Screenshot 2023-04-27 at 9.03.06 PM](https://us1.discourse-cdn.com/elastic/original/3X/9/0/9064e0ea241313275ec8cb73ebe04cdc26c2f97d.png)

Nothing Touched

 ![Screenshot 2023-04-27 at 9.03.17 PM](https://us1.discourse-cdn.com/elastic/original/3X/3/f/3f28f818de265d43bd9eee5f47dd90423ab3a157.png)

Click On Discover

 ![Screenshot 2023-04-27 at 9.04.00 PM](https://us1.discourse-cdn.com/elastic/original/3X/4/0/400f3ff5579bfbf97d445b634494af2e58528309.jpeg)

If I use the filebeat system module with syslog input it does not parse your file... it does parse my syslog on my Mac.

---

<div class="post-metadata">

**Author:** ![ishan.abhinit](https://avatars.discourse-cdn.com/v4/letter/i/d07c76/32.png) [@ishan.abhinit](https://discuss.elastic.co/u/ishan.abhinit)\
**Post date:** [May 1, 2023, 1:33pm UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972/9 "2023-05-01T13:33:30Z")

</div>

Thank you. This worked. I was earlier loading it from the interface on the 'welcome home' page and it was not working. Do you know what could be the reason?

 ![Screenshot 2023-05-01 093150](https://us1.discourse-cdn.com/elastic/original/3X/3/4/346523a7f128e4711a5acf5d50d2665f1ace40f1.png)

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [May 1, 2023, 3:52pm UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972/10 "2023-05-01T15:52:33Z")

</div>

Assuming you mean this, it works exactly the same for me.

 ![Screenshot 2023-05-01 at 8.51.31 AM](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a9be883e49ce651248b68c2097a4e4af2ef4707a.png)

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 29, 2023, 3:53pm UTC](https://discuss.elastic.co/t/kibana-unable-to-parse-syslog-logs/330972/11 "2023-05-29T15:53:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
