# Logstash json to kv output to syslog for splunkindex

**URL:** <https://discuss.elastic.co/t/logstash-json-to-kv-output-to-syslog-for-splunkindex/63452>\
**Category:** Logstash\
**Created:** [October 19, 2016, 10:59pm UTC](https://discuss.elastic.co/t/logstash-json-to-kv-output-to-syslog-for-splunkindex/63452 "2016-10-19T22:59:56Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gmmurugan](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gmmurugan/32/12488_2.png) [@gmmurugan](https://discuss.elastic.co/u/gmmurugan)\
**Post date:** [October 19, 2016, 10:59pm UTC](https://discuss.elastic.co/t/logstash-json-to-kv-output-to-syslog-for-splunkindex/63452/1 "2016-10-19T22:59:56Z")

</div>

I would like to get data from database and add few fields with builtin json to kv conversion and pusing it to syslog/tcp of splunk indexer.

any sample config you can guide?

1. json to kv - any example?
2. add few fields so that splunk indexer can recognize - Done !!
3. sample push it to syslog/tcp.\> tcp works any sample for syslog?

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [October 20, 2016, 12:39am UTC](https://discuss.elastic.co/t/logstash-json-to-kv-output-to-syslog-for-splunkindex/63452/2 "2016-10-20T00:39:42Z")

</div>

LSF is deprecated, you should be using beats instead 🙂

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 20, 2016, 3:38am UTC](https://discuss.elastic.co/t/logstash-json-to-kv-output-to-syslog-for-splunkindex/63452/3 "2016-10-20T03:38:42Z")

</div>

Unless your question really is about [logstash-forwarder](https://github.com/elastic/logstash-forwarder) (which is depreacted, as Mark says) I suggest you edit your post and move it to the Logstash category. Quick answers in the meantime:

1. There's no such built-in conversion, but the json filter or codec can parse your JSON into fields and you can write a small piece of Ruby code in a ruby filter to convert those fields into key/value pairs.
2. Use the `add_field` option of any filter.
3. Use either the syslog or the tcp output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:33am UTC](https://discuss.elastic.co/t/logstash-json-to-kv-output-to-syslog-for-splunkindex/63452/4 "2017-07-06T04:33:29Z")

</div>


