# Logstash split event messages to different syslog servers

**URL:** <https://discuss.elastic.co/t/logstash-split-event-messages-to-different-syslog-servers/355917>\
**Category:** Logstash\
**Tags:** windows\
**Created:** [March 21, 2024, 3:11pm UTC](https://discuss.elastic.co/t/logstash-split-event-messages-to-different-syslog-servers/355917 "2024-03-21T15:11:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Forsaken\_Sherbert\_81](https://avatars.discourse-cdn.com/v4/letter/f/ee7513/32.png) [@Forsaken\_Sherbert\_81](https://discuss.elastic.co/u/Forsaken_Sherbert_81)\
**Post date:** [March 21, 2024, 3:11pm UTC](https://discuss.elastic.co/t/logstash-split-event-messages-to-different-syslog-servers/355917/1 "2024-03-21T15:11:05Z")

</div>

Hi all

I have an specific use-case scenario were I'm testing out Elastic Agent on windows clients.

Some of these logs will be sent to the ELK SIEM for analysis, more debuging and version related information. Other logs like security events Is my goal to send to a separate syslog server. These logs shouldn't be available or sent at all to the ELK SIEM.

Been reading some documentation on Logstash. A Logstash server should fit my purpose, where It has the ability to ship logs do different syslog servers.  
But I don't find any documentation on how to split the trafic depends on the event itself.

So Is my use-case even possible?  
If so, should i configure the split in the agent Itself or should I go for a Logstash for this?

Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 18, 2024, 3:11pm UTC](https://discuss.elastic.co/t/logstash-split-event-messages-to-different-syslog-servers/355917/2 "2024-04-18T15:11:50Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
