# Logstash/rsyslog/json

**URL:** <https://discuss.elastic.co/t/logstash-rsyslog-json/106009>\
**Category:** Logstash\
**Created:** [November 1, 2017, 9:37am UTC](https://discuss.elastic.co/t/logstash-rsyslog-json/106009 "2017-11-01T09:37:11Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [November 1, 2017, 9:37am UTC](https://discuss.elastic.co/t/logstash-rsyslog-json/106009/1 "2017-11-01T09:37:11Z")

</div>

Hi All,

I was trying to setup rsyslog in elasticstack ,so I was trying to follow this article,

> **[How To Centralize Logs with Rsyslog, Logstash, and Elasticsearch on Ubuntu 14.04](https://www.elastic.co/blog/how-to-centralize-logs-with-rsyslog-logstash-and-elasticsearch-on-ubuntu-14-04)**
>
> In this tutorial, you will learn how to create a centralized rsyslog server to store log files from multiple systems and then use Logstash to send them to an Elasticsearch server. From there, you can decide how best to analyze the data.

  
my logstash conf looks exactly similar to the article.

My logstash conf  
,,,  
input {  
udp {  
host =\> "private ip"  
port =\> 5140  
codec =\> "json"  
workers =\> "16"  
queue\_size =\> "100000"  
buffer\_size =\> "100000"  
type =\> "rsyslog"  
}  
}

# This is an empty filter block. You can later add other filters here to further process

# your log lines

filter { }

# This output block will send all events of type "rsyslog" to Elasticsearch at the configured

# host and port into daily indices of the pattern, "rsyslog-YYYY.MM.DD"

output {  
if [type] == "rsyslog" {  
stdout { codec =\> rubydebug }

# elasticsearch {

# hosts =\> ["localhost:9200"]

# index =\> "logstash-%{+YYYY.MM.dd}"

# }

}  
}  
,,,

after setting it up , I tried to run the logstash

bin/logstash -f /etc/logstash/conf.d/ --debug

I get this message

10:31:34.264 [Ruby-0-Thread-38: /usr/share/logstash/logstash-core/lib/logstash/pipeline.rb:532] DEBUG logstash.pipeline - Pushing flush onto pipeline

I tried both stdout rubydebug output and elasticsearch output , still the same

I couldnt figure it out where the problem lies .Please help me to figure out this problem.

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 1, 2017, 9:42am UTC](https://discuss.elastic.co/t/logstash-rsyslog-json/106009/2 "2017-11-01T09:42:14Z")

</div>

How do you know that any messages from remote servers are even reaching Logstash? You can use nc/netcat in listen mode to snoop the traffic (with Logstash shut down).

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [November 1, 2017, 9:46am UTC](https://discuss.elastic.co/t/logstash-rsyslog-json/106009/3 "2017-11-01T09:46:06Z")

</div>

Thanks for the reply, I use tshark to confirm if i get the data

tshark -f 'port 5140'  
tshark: Lua: Error during loading:  
[string "/usr/share/wireshark/init.lua"]:46: dofile has been disabled due to running Wireshark as superuser. See [http://wiki.wireshark.org/CaptureSetup/CapturePrivileges](http://wiki.wireshark.org/CaptureSetup/CapturePrivileges) for help in running Wireshark as an unprivileged user.  
Running as user "root" and group "root". This could be dangerous.  
Capturing on 'eth0'  
1 0.000000 -\> TCP 78 57595→5140 [SYN] Seq=0 Win=32768 Len=0 MSS=1460 WS=8 SACK\_PERM=1 TSval=1 TSecr=0  
2 0.000023 -\> TCP 54 5140→57595 [RST, ACK] Seq=1 Ack=1 Win=0 Len=0

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 1, 2017, 11:03am UTC](https://discuss.elastic.co/t/logstash-rsyslog-json/106009/4 "2017-11-01T11:03:44Z")

</div>

So a TCP connection attempt (which is rejected) but you're only listening to UDP datagrams.

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [November 2, 2017, 9:10am UTC](https://discuss.elastic.co/t/logstash-rsyslog-json/106009/5 "2017-11-02T09:10:29Z")

</div>

Yes Magnus, it seems to be only udp

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [November 2, 2017, 11:58am UTC](https://discuss.elastic.co/t/logstash-rsyslog-json/106009/6 "2017-11-02T11:58:25Z")

</div>

Now Iam receiving docs in the Kibana but it looks this am not sure where the problem lies

![image](https://us1.discourse-cdn.com/elastic/original/3X/1/f/1f7ce6ff948739c2e2b0bc09df1bf418c2927d04.png)

I tried to tcpdump and check if there is data , most of data length is 0 and few are having data length of 3 and less values.

How to proceed with this?

Thanks,  
Raj

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [November 2, 2017, 12:09pm UTC](https://discuss.elastic.co/t/logstash-rsyslog-json/106009/7 "2017-11-02T12:09:03Z")

</div>

Have you looked at what rsyslog actually is sending, to take Logstash out of the equation?

---

<div class="post-metadata">

**Author:** ![Raj\_Kumar](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/raj_kumar/32/25420_2.png) [@Raj\_Kumar](https://discuss.elastic.co/u/Raj_Kumar)\
**Post date:** [November 6, 2017, 1:17pm UTC](https://discuss.elastic.co/t/logstash-rsyslog-json/106009/8 "2017-11-06T13:17:30Z")

</div>

there was some issues from client server side,now am able to receive it ,thanks for the help

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 4, 2017, 1:17pm UTC](https://discuss.elastic.co/t/logstash-rsyslog-json/106009/9 "2017-12-04T13:17:56Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
