# Logstash and syslog: logs from specific IP

**URL:** <https://discuss.elastic.co/t/logstash-and-syslog-logs-from-specific-ip/39976>\
**Category:** Logstash\
**Created:** [January 24, 2016, 7:41pm UTC](https://discuss.elastic.co/t/logstash-and-syslog-logs-from-specific-ip/39976 "2016-01-24T19:41:30Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![maciej.kola](https://avatars.discourse-cdn.com/v4/letter/m/eb8c5e/32.png) [@maciej.kola](https://discuss.elastic.co/u/maciej.kola)\
**Post date:** [January 24, 2016, 7:41pm UTC](https://discuss.elastic.co/t/logstash-and-syslog-logs-from-specific-ip/39976/1 "2016-01-24T19:41:30Z")

</div>

Hi there,

Firstly, let me just say that I am new in elk stack but I already think it's great solution.  
I use elk with syslog, to collect and search logs from multiple client systems. What I did so far:  
syslog is listening on 514 port, processing every message (saving to specific file) and redirecting every message also to localhost 1514 ( to logstash).

input{  
udp  
{  
host =\> "127.0.0.1"  
port =\> 1514  
type =\> syslog  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

My question is: can I do something, to group my logs per IP of client? For example, I want to show only logs from client X (A.B.C.D ip address) - how to do it? Should I create seprate index for each client? or maybe some filter?

Please help,  
Maciej

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 24, 2016, 7:44pm UTC](https://discuss.elastic.co/t/logstash-and-syslog-logs-from-specific-ip/39976/2 "2016-01-24T19:44:38Z")

</div>

Where do you want to group them, in ES?

---

<div class="post-metadata">

**Author:** ![maciej.kola](https://avatars.discourse-cdn.com/v4/letter/m/eb8c5e/32.png) [@maciej.kola](https://discuss.elastic.co/u/maciej.kola)\
**Post date:** [January 24, 2016, 8:03pm UTC](https://discuss.elastic.co/t/logstash-and-syslog-logs-from-specific-ip/39976/3 "2016-01-24T20:03:04Z")

</div>

I'm not sure where I want to group them. What I want is to show all messages from client X on one page, build visualization for only one client etc. Now all messages from all clients are in one place and to find specific client I need to use "search" option.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 24, 2016, 9:02pm UTC](https://discuss.elastic.co/t/logstash-and-syslog-logs-from-specific-ip/39976/4 "2016-01-24T21:02:38Z")

</div>

Sounds like via Kibana then.

You can use a filter to do this, eg `hostname: hostname.example.com`.

---

<div class="post-metadata">

**Author:** ![maciej.kola](https://avatars.discourse-cdn.com/v4/letter/m/eb8c5e/32.png) [@maciej.kola](https://discuss.elastic.co/u/maciej.kola)\
**Post date:** [January 25, 2016, 8:33am UTC](https://discuss.elastic.co/t/logstash-and-syslog-logs-from-specific-ip/39976/5 "2016-01-25T08:33:38Z")

</div>

Can you please tell me how to set up this filter in kibana? I tried to enter this in "search" field but it doesn't work. I though filters are placed in logstash but maybe I'm wrong.

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [January 25, 2016, 8:55am UTC](https://discuss.elastic.co/t/logstash-and-syslog-logs-from-specific-ip/39976/6 "2016-01-25T08:55:00Z")

</div>

They are different types of filters.

So if you put a search into KB, what happens?

---

<div class="post-metadata">

**Author:** ![maciej.kola](https://avatars.discourse-cdn.com/v4/letter/m/eb8c5e/32.png) [@maciej.kola](https://discuss.elastic.co/u/maciej.kola)\
**Post date:** [January 27, 2016, 10:04am UTC](https://discuss.elastic.co/t/logstash-and-syslog-logs-from-specific-ip/39976/7 "2016-01-27T10:04:32Z")

</div>

Mark - thank you for your help. I think I solved my problem: instead of redirecting my syslog to logstash port 1514, I changed my logstash configuration:

input  
{  
file  
{  
path =\> ["/path/to/saved/logs/1/\*.log"]  
start\_position =\> "beginning"  
type =\> "syslog"  
}

```
            file
            {
                    path => ["/path/to/saved/logs/2/*.log"]
                    start_position => "beginning"
                    type => "syslog"
            }

```

}

Now, as a search criteria I can choose "path" value (for example /path/to/saved/logs/2/syslog.log). If so, only logs from one host (host 2) would be shown. Another thing is I don't understand yet what are the pros and cons of such solution - I think I will open a new discussion about it.

Maciej

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:14am UTC](https://discuss.elastic.co/t/logstash-and-syslog-logs-from-specific-ip/39976/8 "2017-07-06T05:14:07Z")

</div>


