# Logstash config file with syslog and json

**URL:** <https://discuss.elastic.co/t/logstash-config-file-with-syslog-and-json/229984>\
**Category:** Logstash\
**Created:** [April 27, 2020, 3:13pm UTC](https://discuss.elastic.co/t/logstash-config-file-with-syslog-and-json/229984 "2020-04-27T15:13:01Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sublimesol](https://avatars.discourse-cdn.com/v4/letter/s/4bbf92/32.png) [@sublimesol](https://discuss.elastic.co/u/sublimesol)\
**Post date:** [April 27, 2020, 3:13pm UTC](https://discuss.elastic.co/t/logstash-config-file-with-syslog-and-json/229984/1 "2020-04-27T15:13:01Z")

</div>

Hi all,  
Im very new to ELK and I've recently moved my firewall logging from Splunk to ELK - i currently have my palo alto firewall logging to ELK and I can see syslog messages in being displayed in dashboard in KIbana.

All my historic data has been exported from splunk in a json file. What i would like to do is import this into ELK.

Is it a case of adding a new input into the existing logstash config file?

can i make a copy of the existing config file, rename it and just change the input to file rather syslog?

if someone can help with an example snippet of config file to see how I can achieve this?

Thanks  
SS

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2020, 3:16pm UTC](https://discuss.elastic.co/t/logstash-config-file-with-syslog-and-json/229984/2 "2020-05-25T15:16:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
