# Logstash: how to include/modify facility/priority

**URL:** <https://discuss.elastic.co/t/logstash-how-to-include-modify-facility-priority/20352>\
**Category:** Elasticsearch\
**Created:** [October 20, 2014, 8:50pm UTC](https://discuss.elastic.co/t/logstash-how-to-include-modify-facility-priority/20352 "2014-10-20T20:50:28Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![paulo\_bruck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paulo_bruck/32/22285_2.png) [@paulo\_bruck](https://discuss.elastic.co/u/paulo_bruck)\
**Post date:** [October 20, 2014, 8:50pm UTC](https://discuss.elastic.co/t/logstash-how-to-include-modify-facility-priority/20352/1 "2014-10-20T20:50:28Z")

</div>

Hi Folks

I m trying to insert/modify via logstash priority and facility.

Using debian wheezy + rsyslog + logstash 1.4.2 and elasticsearch 1.1.1.

part of my rsyslog to undersand that I wanna:

/etc/rsyslog.conf:  
.....

# auth

auth.=emerg -/var/log/auth/auth\_emerg.log  
auth.=alert -/var/log/auth/auth\_alert.log  
auth.=crit -/var/log/auth/auth\_crit.log  
auth.=err -/var/log/auth/auth\_err.log  
auth.=warning -/var/log/auth/auth\_warning.log  
auth.=notice -/var/log/auth/auth\_notice.log  
auth.=info -/var/log/auth/auth\_info.log  
auth.=debug -/var/log/auth/auth\_debug.log

# authpriv

authpriv.=emerg -/var/log/authpriv/authpriv\_emerg.log  
authpriv.=alert -/var/log/authpriv/authpriv\_alert.log  
authpriv.=crit -/var/log/authpriv/authpriv\_crit.log  
......

/etc/logstash/conf.d/syslog.conf  
input {  
file {  
path =\> "/var/log/auth/auth\__.log"  
type =\> "syslog"  
}  
file {  
path =\> "/var/log/authpriv/authpriv\__.log"  
type =\> "syslog"  
}  
file {  
path =\> "/var/log/cron/cron\_\*.log"  
type =\> "syslog"

.....

filter {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp}  
%{SYSLOGHOST:syslog\_hostname}  
%{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?:  
%{GREEDYDATA:syslog\_message}" }  
}  
date {  
locale =\> "en"  
match =\> [ "syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd  
HH:mm:ss", "ISO8601" ]  
}  
}

output {  
elasticsearch { host =\> localhost }  
stdout { codec =\> rubydebug }  
}

json of one os syslog entries:

{  
"\_index": "logstash-2014.10.20",  
"\_type": "syslog",  
"\_id": "57KDKSXKSeCy9VFDr1Arlw",  
"\_score": null,  
"\_source": {  
"message": "Oct 20 18:10:01 wheezy CRON[5576]: pam\_unix(cron:session): session closed for user www-data",  
"@version": "1",  
"@timestamp": "2014-10-20T20:10:01.000Z",  
"type": "syslog",  
"host": "wheezy",  
"path": "/var/log/authpriv/authpriv\_info.log",  
"tags": [  
"\_grokparsefailure"  
],  
"syslog\_timestamp": "Oct 20 18:10:01",  
"syslog\_hostname": "wheezy",  
"syslog\_program": "CRON",  
"syslog\_pid": "5576",  
"syslog\_message": "pam\_unix(cron:session): session closed for user www-data"  
},  
"sort": [  
1413835801000,  
1413835801000  
]  
}

How can I include facility priority knowing that at PATH I already have this information?  
explo: path =\> "/var/log/auth/auth\_emerg.log, /var/log/auth/auth\_crit.log..."

best regards

BTW is there a book or another doc to read ? I've been reading [logstah.net/docs](http://logstah.net/docs) but it is not enough to me...80)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/ad3fe421-0027-4986-99b4-a10b8ae1741b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/ad3fe421-0027-4986-99b4-a10b8ae1741b%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![paulo\_bruck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/paulo_bruck/32/22285_2.png) [@paulo\_bruck](https://discuss.elastic.co/u/paulo_bruck)\
**Post date:** [October 21, 2014, 4:24pm UTC](https://discuss.elastic.co/t/logstash-how-to-include-modify-facility-priority/20352/2 "2014-10-21T16:24:49Z")

</div>

Hi

For whoever is interested below the solutions that I found 80)

Em segunda-feira, 20 de outubro de 2014 18h50min28s UTC-2, paulo bruck  
escreveu:

> Hi Folks
> 
> I m trying to insert/modify via logstash priority and facility.
> 
> Using debian wheezy + rsyslog + logstash 1.4.2 and elasticsearch 1.1.1.
> 
> part of my rsyslog to undersand that I wanna:
> 
> /etc/rsyslog.conf:  
> .....
> 
> # auth
> 
> auth.=emerg -/var/log/auth/auth\_emerg.log  
> auth.=alert -/var/log/auth/auth\_alert.log  
> auth.=crit -/var/log/auth/auth\_crit.log  
> auth.=err -/var/log/auth/auth\_err.log  
> auth.=warning -/var/log/auth/auth\_warning.log  
> auth.=notice -/var/log/auth/auth\_notice.log  
> auth.=info -/var/log/auth/auth\_info.log  
> auth.=debug -/var/log/auth/auth\_debug.log
> 
> # authpriv
> 
> authpriv.=emerg -/var/log/authpriv/authpriv\_emerg.log  
> authpriv.=alert -/var/log/authpriv/authpriv\_alert.log  
> authpriv.=crit -/var/log/authpriv/authpriv\_crit.log  
> ......
> 
> /etc/logstash/conf.d/syslog.conf  
> input {  
> file {  
> path =\> "/var/log/auth/auth\__.log"  
> type =\> "syslog"  
> }  
> file {  
> path =\> "/var/log/authpriv/authpriv\__.log"  
> type =\> "syslog"  
> }  
> file {  
> path =\> "/var/log/cron/cron\_\*.log"  
> type =\> "syslog"
> 
> .....
> 
> filter {  
> grok {  
> match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp}  
> %{SYSLOGHOST:syslog\_hostname}  
> %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?:  
> %{GREEDYDATA:syslog\_message}" }  
> }  
> date {  
> locale =\> "en"  
> match =\> [ "syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd  
> HH:mm:ss", "ISO8601" ]  
> }  
> }

- 

```
 syslog_pri { } if [path] =~ "auth" { mutate { replace 

```

=\> { "syslog\_facility" =\> "auth" }}} if [path] =~ "auth" { mutate {  
replace =\> { "syslog\_facility\_code" =\> "4" }}} if [path] =~  
"authpriv" { mutate { replace =\> { "syslog\_facility" =\> "authpriv" }}  
} if [path] =~ "authpriv" { mutate { replace =\> {  
"syslog\_facility\_code" =\> "4" }}} if [path] =~ "cron" { mutate {  
replace =\> { "syslog\_facility" =\> "cron" }}}......... if [path] =~  
"emerg" { mutate { replace =\> { "syslog\_severity" =\> "emerg" }}} if  
[path] =~ "emerg" { mutate { replace =\> { "syslog\_severity\_code" =\> "0" }}}  
if [path] =~ "alert" { mutate { replace =\> { "syslog\_severity" =\>  
"alert" }}} if [path] =~ "alert" { mutate { replace =\> {  
"syslog\_severity\_code" =\> "1" }}} if [path] =~ "crit" { mutate {  
replace =\> { "syslog\_severity" =\> "crit" }}} ....\*

> output {  
> elasticsearch { host =\> localhost }  
> stdout { codec =\> rubydebug }  
> }
> 
> json of one os syslog entries:
> 
> {  
> "\_index": "logstash-2014.10.20",  
> "\_type": "syslog",  
> "\_id": "57KDKSXKSeCy9VFDr1Arlw",  
> "\_score": null,  
> "\_source": {  
> "message": "Oct 20 18:10:01 wheezy CRON[5576]: pam\_unix(cron:session): session closed for user www-data",  
> "@version": "1",  
> "@timestamp": "2014-10-20T20:10:01.000Z",  
> "type": "syslog",  
> "host": "wheezy",  
> "path": "/var/log/authpriv/authpriv\_info.log",  
> "tags": [  
> "\_grokparsefailure"  
> ],  
> "syslog\_timestamp": "Oct 20 18:10:01",  
> "syslog\_hostname": "wheezy",  
> "syslog\_program": "CRON",  
> "syslog\_pid": "5576",  
> "syslog\_message": "pam\_unix(cron:session): session closed for user www-data"  
> },  
> "sort": [  
> 1413835801000,  
> 1413835801000  
> ]  
> }
> 
> How can I include facility priority knowing that at PATH I already have this information?  
> explo: path =\> "/var/log/auth/auth\_emerg.log, /var/log/auth/auth\_crit.log..."
> 
> best regards
> 
> BTW is there a book or another doc to read ? I've been reading [logstah.net/docs](http://logstah.net/docs) but it is not enough to me...80)

Em segunda-feira, 20 de outubro de 2014 18h50min28s UTC-2, paulo bruck  
escreveu:

> Hi Folks
> 
> I m trying to insert/modify via logstash priority and facility.
> 
> Using debian wheezy + rsyslog + logstash 1.4.2 and elasticsearch 1.1.1.
> 
> part of my rsyslog to undersand that I wanna:
> 
> /etc/rsyslog.conf:  
> .....
> 
> # auth
> 
> auth.=emerg -/var/log/auth/auth\_emerg.log  
> auth.=alert -/var/log/auth/auth\_alert.log  
> auth.=crit -/var/log/auth/auth\_crit.log  
> auth.=err -/var/log/auth/auth\_err.log  
> auth.=warning -/var/log/auth/auth\_warning.log  
> auth.=notice -/var/log/auth/auth\_notice.log  
> auth.=info -/var/log/auth/auth\_info.log  
> auth.=debug -/var/log/auth/auth\_debug.log
> 
> # authpriv
> 
> authpriv.=emerg -/var/log/authpriv/authpriv\_emerg.log  
> authpriv.=alert -/var/log/authpriv/authpriv\_alert.log  
> authpriv.=crit -/var/log/authpriv/authpriv\_crit.log  
> ......
> 
> /etc/logstash/conf.d/syslog.conf  
> input {  
> file {  
> path =\> "/var/log/auth/auth\__.log"  
> type =\> "syslog"  
> }  
> file {  
> path =\> "/var/log/authpriv/authpriv\__.log"  
> type =\> "syslog"  
> }  
> file {  
> path =\> "/var/log/cron/cron\_\*.log"  
> type =\> "syslog"
> 
> .....
> 
> filter {  
> grok {  
> match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp}  
> %{SYSLOGHOST:syslog\_hostname}  
> %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?:  
> %{GREEDYDATA:syslog\_message}" }  
> }  
> date {  
> locale =\> "en"  
> match =\> [ "syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd  
> HH:mm:ss", "ISO8601" ]  
> }  
> }
> 
> output {  
> elasticsearch { host =\> localhost }  
> stdout { codec =\> rubydebug }  
> }
> 
> json of one os syslog entries:
> 
> {  
> "\_index": "logstash-2014.10.20",  
> "\_type": "syslog",  
> "\_id": "57KDKSXKSeCy9VFDr1Arlw",  
> "\_score": null,  
> "\_source": {  
> "message": "Oct 20 18:10:01 wheezy CRON[5576]: pam\_unix(cron:session): session closed for user www-data",  
> "@version": "1",  
> "@timestamp": "2014-10-20T20:10:01.000Z",  
> "type": "syslog",  
> "host": "wheezy",  
> "path": "/var/log/authpriv/authpriv\_info.log",  
> "tags": [  
> "\_grokparsefailure"  
> ],  
> "syslog\_timestamp": "Oct 20 18:10:01",  
> "syslog\_hostname": "wheezy",  
> "syslog\_program": "CRON",  
> "syslog\_pid": "5576",  
> "syslog\_message": "pam\_unix(cron:session): session closed for user www-data"  
> },  
> "sort": [  
> 1413835801000,  
> 1413835801000  
> ]  
> }
> 
> How can I include facility priority knowing that at PATH I already have this information?  
> explo: path =\> "/var/log/auth/auth\_emerg.log, /var/log/auth/auth\_crit.log..."
> 
> best regards
> 
> BTW is there a book or another doc to read ? I've been reading [logstah.net/docs](http://logstah.net/docs) but it is not enough to me...80)

Em segunda-feira, 20 de outubro de 2014 18h50min28s UTC-2, paulo bruck  
escreveu:

> Hi Folks
> 
> I m trying to insert/modify via logstash priority and facility.
> 
> Using debian wheezy + rsyslog + logstash 1.4.2 and elasticsearch 1.1.1.
> 
> part of my rsyslog to undersand that I wanna:
> 
> /etc/rsyslog.conf:  
> .....
> 
> # auth
> 
> auth.=emerg -/var/log/auth/auth\_emerg.log  
> auth.=alert -/var/log/auth/auth\_alert.log  
> auth.=crit -/var/log/auth/auth\_crit.log  
> auth.=err -/var/log/auth/auth\_err.log  
> auth.=warning -/var/log/auth/auth\_warning.log  
> auth.=notice -/var/log/auth/auth\_notice.log  
> auth.=info -/var/log/auth/auth\_info.log  
> auth.=debug -/var/log/auth/auth\_debug.log
> 
> # authpriv
> 
> authpriv.=emerg -/var/log/authpriv/authpriv\_emerg.log  
> authpriv.=alert -/var/log/authpriv/authpriv\_alert.log  
> authpriv.=crit -/var/log/authpriv/authpriv\_crit.log  
> ......
> 
> /etc/logstash/conf.d/syslog.conf  
> input {  
> file {  
> path =\> "/var/log/auth/auth\__.log"  
> type =\> "syslog"  
> }  
> file {  
> path =\> "/var/log/authpriv/authpriv\__.log"  
> type =\> "syslog"  
> }  
> file {  
> path =\> "/var/log/cron/cron\_\*.log"  
> type =\> "syslog"
> 
> .....
> 
> filter {  
> grok {  
> match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp}  
> %{SYSLOGHOST:syslog\_hostname}  
> %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?:  
> %{GREEDYDATA:syslog\_message}" }  
> }  
> date {  
> locale =\> "en"  
> match =\> [ "syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd  
> HH:mm:ss", "ISO8601" ]  
> }  
> }
> 
> output {  
> elasticsearch { host =\> localhost }  
> stdout { codec =\> rubydebug }  
> }
> 
> json of one os syslog entries:
> 
> {  
> "\_index": "logstash-2014.10.20",  
> "\_type": "syslog",  
> "\_id": "57KDKSXKSeCy9VFDr1Arlw",  
> "\_score": null,  
> "\_source": {  
> "message": "Oct 20 18:10:01 wheezy CRON[5576]: pam\_unix(cron:session): session closed for user www-data",  
> "@version": "1",  
> "@timestamp": "2014-10-20T20:10:01.000Z",  
> "type": "syslog",  
> "host": "wheezy",  
> "path": "/var/log/authpriv/authpriv\_info.log",  
> "tags": [  
> "\_grokparsefailure"  
> ],  
> "syslog\_timestamp": "Oct 20 18:10:01",  
> "syslog\_hostname": "wheezy",  
> "syslog\_program": "CRON",  
> "syslog\_pid": "5576",  
> "syslog\_message": "pam\_unix(cron:session): session closed for user www-data"  
> },  
> "sort": [  
> 1413835801000,  
> 1413835801000  
> ]  
> }
> 
> How can I include facility priority knowing that at PATH I already have this information?  
> explo: path =\> "/var/log/auth/auth\_emerg.log, /var/log/auth/auth\_crit.log..."
> 
> best regards
> 
> BTW is there a book or another doc to read ? I've been reading [logstah.net/docs](http://logstah.net/docs) but it is not enough to me...80)

Em segunda-feira, 20 de outubro de 2014 18h50min28s UTC-2, paulo bruck  
escreveu:

> Hi Folks
> 
> I m trying to insert/modify via logstash priority and facility.
> 
> Using debian wheezy + rsyslog + logstash 1.4.2 and elasticsearch 1.1.1.
> 
> part of my rsyslog to undersand that I wanna:
> 
> /etc/rsyslog.conf:  
> .....
> 
> # auth
> 
> auth.=emerg -/var/log/auth/auth\_emerg.log  
> auth.=alert -/var/log/auth/auth\_alert.log  
> auth.=crit -/var/log/auth/auth\_crit.log  
> auth.=err -/var/log/auth/auth\_err.log  
> auth.=warning -/var/log/auth/auth\_warning.log  
> auth.=notice -/var/log/auth/auth\_notice.log  
> auth.=info -/var/log/auth/auth\_info.log  
> auth.=debug -/var/log/auth/auth\_debug.log
> 
> # authpriv
> 
> authpriv.=emerg -/var/log/authpriv/authpriv\_emerg.log  
> authpriv.=alert -/var/log/authpriv/authpriv\_alert.log  
> authpriv.=crit -/var/log/authpriv/authpriv\_crit.log  
> ......
> 
> /etc/logstash/conf.d/syslog.conf  
> input {  
> file {  
> path =\> "/var/log/auth/auth\__.log"  
> type =\> "syslog"  
> }  
> file {  
> path =\> "/var/log/authpriv/authpriv\__.log"  
> type =\> "syslog"  
> }  
> file {  
> path =\> "/var/log/cron/cron\_\*.log"  
> type =\> "syslog"
> 
> .....
> 
> filter {  
> grok {  
> match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp}  
> %{SYSLOGHOST:syslog\_hostname}  
> %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?:  
> %{GREEDYDATA:syslog\_message}" }  
> }  
> date {  
> locale =\> "en"  
> match =\> [ "syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd  
> HH:mm:ss", "ISO8601" ]  
> }  
> }
> 
> output {  
> elasticsearch { host =\> localhost }  
> stdout { codec =\> rubydebug }  
> }
> 
> json of one os syslog entries:
> 
> {  
> "\_index": "logstash-2014.10.20",  
> "\_type": "syslog",  
> "\_id": "57KDKSXKSeCy9VFDr1Arlw",  
> "\_score": null,  
> "\_source": {  
> "message": "Oct 20 18:10:01 wheezy CRON[5576]: pam\_unix(cron:session): session closed for user www-data",  
> "@version": "1",  
> "@timestamp": "2014-10-20T20:10:01.000Z",  
> "type": "syslog",  
> "host": "wheezy",  
> "path": "/var/log/authpriv/authpriv\_info.log",  
> "tags": [  
> "\_grokparsefailure"  
> ],  
> "syslog\_timestamp": "Oct 20 18:10:01",  
> "syslog\_hostname": "wheezy",  
> "syslog\_program": "CRON",  
> "syslog\_pid": "5576",  
> "syslog\_message": "pam\_unix(cron:session): session closed for user www-data"  
> },  
> "sort": [  
> 1413835801000,  
> 1413835801000  
> ]  
> }
> 
> How can I include facility priority knowing that at PATH I already have this information?  
> explo: path =\> "/var/log/auth/auth\_emerg.log, /var/log/auth/auth\_crit.log..."
> 
> best regards
> 
> BTW is there a book or another doc to read ? I've been reading [logstah.net/docs](http://logstah.net/docs) but it is not enough to me...80)

--  
You received this message because you are subscribed to the Google Groups "elasticsearch" group.  
To unsubscribe from this group and stop receiving emails from it, send an email to [elasticsearch+unsubscribe@googlegroups.com](mailto:elasticsearch+unsubscribe@googlegroups.com).  
To view this discussion on the web visit [https://groups.google.com/d/msgid/elasticsearch/2f756f58-a7f7-4e0b-a9c8-66072a845b4b%40googlegroups.com](https://groups.google.com/d/msgid/elasticsearch/2f756f58-a7f7-4e0b-a9c8-66072a845b4b%40googlegroups.com).  
For more options, visit [https://groups.google.com/d/optout](https://groups.google.com/d/optout).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 12:54am UTC](https://discuss.elastic.co/t/logstash-how-to-include-modify-facility-priority/20352/3 "2017-07-06T00:54:40Z")

</div>


