# Logstash output syslog : how to remove added {host} field?

**URL:** <https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246>\
**Category:** Logstash\
**Created:** [January 5, 2021, 5:11pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246 "2021-01-05T17:11:36Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [January 5, 2021, 5:11pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246/1 "2021-01-05T17:11:36Z")

</div>

Hello there !

I have to forward kafka logs to syslog relay. I know it's weird but I have to.

Here is logstash conf :

```
#kafka input
input {
  kafka {
    topics => ["test"]
    codec => json
    bootstrap_servers => "kafka1:9092"

#keep only message of log
filter
{
prune {
  whitelist_names => ["^message$"]
  }
}

#output to syslog 
output {
  syslog {
    host => "1.2.3.4"
    port => 514
    protocol => "tcp"
    appname => ""
    msgid => ""
    sourcehost => ""
    procid => ""
  }
}

```

But this was not enough, so I edited syslog output plugin logstash-output-syslog-3.0.5 (syslog.rb) :

Full plugin code is here : [https://github.com/logstash-plugins/logstash-output-syslog/blob/master/lib/logstash/outputs/syslog.rb](https://github.com/logstash-plugins/logstash-output-syslog/blob/master/lib/logstash/outputs/syslog.rb)

```
[...]

  def publish(event, payload)
    appname = event.sprintf(@appname)
    procid = event.sprintf(@procid)
    sourcehost = event.sprintf(@sourcehost)

    message = payload.to_s.rstrip.gsub(/[\r][\n]/, "\n").gsub(/[\n]/, '\n')

    # fallback to pri 13 (facility 1, severity 5)
    if @use_labels
      facility_code = (FACILITY_LABELS.index(event.sprintf(@facility)) || 1)
      severity_code = (SEVERITY_LABELS.index(event.sprintf(@severity)) || 5)
      priority = (facility_code * 8) + severity_code
    else
      priority = Integer(event.sprintf(@priority)) rescue 13
      priority = 13 if (priority < 0 || priority > 191)
    end

    if @is_rfc3164
      timestamp = event.sprintf("%{+MMM dd HH:mm:ss}")
#original code	  
# syslog_msg = "<#{priority.to_s}>#{timestamp} #{sourcehost} #{appname}[#{procid}]: #{message}"

#new code to have only priority and message 
      syslog_msg = "<#{priority.to_s}>#{message}"
    else
      msgid = event.sprintf(@msgid)
      timestamp = event.sprintf("%{+YYYY-MM-dd'T'HH:mm:ss.SSSZZ}")
      syslog_msg = "<#{priority.to_s}>1 #{timestamp} #{sourcehost} #{appname} #{procid} #{msgid} - #{message}"
      syslog_msg = "<#{priority.to_s}>#{message}"
    end

[...] 

```

When event is received on the syslog relay, I have this :

> \<13\>%{host} Jan 5 16:42:29 server1 misc-centreon(misc\_centreon)[61665]: INFO: running

But I expect this :

> \<13\>Jan 5 16:42:29 server1 misc-centreon(misc\_centreon)[61665]: INFO: running

Where do comes from {host} at the beginning of the message ? I can't succeed to find it in plugin code and remove it

Can you help me ?

Thanks ! 🙂

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [January 5, 2021, 5:23pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246/2 "2021-01-05T17:23:22Z")

</div>

You do not appear to be using any of the features of the syslog output. Why not replace it with a tcp output instead of rewriting the syslog output to do no enrichment of the message?

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [January 5, 2021, 9:47pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246/3 "2021-01-05T21:47:35Z")

</div>

Indeed I don't use main syslog features but I have to respect a minimum the form as log will be processed like a log coming directly from a machine once in the syslog relay.

I just have to remove %{host} and I don't understand how to do it when looking at the code

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [January 6, 2021, 5:14pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246/4 "2021-01-06T17:14:04Z")

</div>

As reported here -\> [Logstash syslog output ignores message](https://discuss.elastic.co/t/logstash-syslog-output-ignores-message/220434) it looks like there is like a bug and the workaround is to add the field "host" in filter to be taken into account by the plugin

So, for my needs I use this :

```
#keep only message of log and add empty host field
filter
{
prune {
  whitelist_names => ["^message$"]
  }
mutate {
  add_field => {"host" => ""}
  }
}

```

This way, received log by syslog relay is :

> \<13\> Jan 5 16:42:29 server1 misc-centreon(misc\_centreon)[61665]: INFO: running

Unfortunately, as you can see, there i still a space after \<13\> but it's already that !

I don't understand why it is so hard to find where does comes from this %{host} field. If someone has a better comprehension... 😉

---

<div class="post-metadata">

**Author:** ![mtudisco](https://avatars.discourse-cdn.com/v4/letter/m/3d9bf3/32.png) [@mtudisco](https://discuss.elastic.co/u/mtudisco)\
**Post date:** [January 6, 2021, 5:34pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246/5 "2021-01-06T17:34:10Z")

</div>

Hi,  
The way i manged to solve my problem was using plain codec:

```
syslog {
		        host => "X.X.X.X"
		        port => 514
		        protocol => "tcp"
		        rfc => rfc5424
                sourcehost => "%{source_ip}"
                appname => "%{event_type}"
                codec => plain { format => "%{message}" }
	           }

```

hope it helps

---

<div class="post-metadata">

**Author:** ![Travis](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/travis/32/54079_2.png) [@Travis](https://discuss.elastic.co/u/Travis)\
**Post date:** [January 6, 2021, 5:48pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246/6 "2021-01-06T17:48:45Z")

</div>

Yes perfect... It works 🙂

Thanks a lot !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 3, 2021, 5:48pm UTC](https://discuss.elastic.co/t/logstash-output-syslog-how-to-remove-added-host-field/260246/7 "2021-02-03T17:48:48Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
