# Logstash Docker Container Syslog input

**URL:** <https://discuss.elastic.co/t/logstash-docker-container-syslog-input/304874>\
**Category:** Logstash\
**Tags:** docker\
**Created:** [May 16, 2022, 9:46pm UTC](https://discuss.elastic.co/t/logstash-docker-container-syslog-input/304874 "2022-05-16T21:46:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![doublejz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/doublejz/32/105743_2.png) [@doublejz](https://discuss.elastic.co/u/doublejz)\
**Post date:** [May 16, 2022, 9:46pm UTC](https://discuss.elastic.co/t/logstash-docker-container-syslog-input/304874/1 "2022-05-16T21:46:08Z")

</div>

I've been fighting this the last couple days and well, I give up and need help. So I have an ELK stack docker setup and I'm simply trying to setup logstash to accept syslog directly to it. I pictured random port 5514 and but the following in docker-elk/logstash/config/logstash.yml (which is reference as a volume in the composer file). Any way, no matter what I seem to put in the yml file, I get an error stating

`error: yaml: line X: could not find expected ':'`

I've tried the following:

```auto
> ---
> http.host: "192.168.1.227"
> input {
> udp {
> host => "localhost"
> port => 5514
> codec => "json"
> type => "rsyslog"
> }
> }
> 
> filter { }
> 
> output {
> if [type] == "rsyslog" {
> elasticsearch {
> hosts => ["localhost:9200"]
> }
> }
> }

```

```auto
---
http.host: "192.168.1.227"

input {
  tcp {
    port => 5514
    type => syslog
  }
  udp {
    port => 5514
    type => syslog
  }
}

filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}

output {
  elasticsearch { hosts => ["localhost:9200"] }
  stdout { codec => rubydebug }
}

```

```auto
---
http.host: "192.168.1.227"

input {
  tcp {
    port => 5514
    type => syslog
  }
}

```

Any suggestions would be greatly appreciated.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 16, 2022, 10:14pm UTC](https://discuss.elastic.co/t/logstash-docker-container-syslog-input/304874/2 "2022-05-16T22:14:08Z")

</div>

> [@doublejz](#):
>
> ```auto
> input {
> ...
> }
> filter { }
> output {
> ...
> }
> 
> ```

The pipeline confuration should not be in logstash.yml, it should be in a separate file that you can point to using -f [command line option](https://www.elastic.co/guide/en/logstash/current/running-logstash-command-line.html#command-line-flags) (or you can use [pipelines.yml](https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html)).

---

<div class="post-metadata">

**Author:** ![doublejz](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/doublejz/32/105743_2.png) [@doublejz](https://discuss.elastic.co/u/doublejz)\
**Post date:** [May 16, 2022, 10:30pm UTC](https://discuss.elastic.co/t/logstash-docker-container-syslog-input/304874/3 "2022-05-16T22:30:18Z")

</div>

Oh ffs, I knew that. ty!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 13, 2022, 10:30pm UTC](https://discuss.elastic.co/t/logstash-docker-container-syslog-input/304874/4 "2022-06-13T22:30:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
