# Logstash, syslog, ECS and Kibana Logs / SIEM

**URL:** <https://discuss.elastic.co/t/logstash-syslog-ecs-and-kibana-logs-siem/274789>\
**Category:** Logstash\
**Created:** [June 2, 2021, 5:56pm UTC](https://discuss.elastic.co/t/logstash-syslog-ecs-and-kibana-logs-siem/274789 "2021-06-02T17:56:30Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![egli](https://avatars.discourse-cdn.com/v4/letter/e/ed655f/32.png) [@egli](https://discuss.elastic.co/u/egli)\
**Post date:** [June 2, 2021, 5:56pm UTC](https://discuss.elastic.co/t/logstash-syslog-ecs-and-kibana-logs-siem/274789/1 "2021-06-02T17:56:30Z")

</div>

Hi, I have logstash working as a central syslog server using syslog\_pri plugin and sending the events to elasticsearch. I would like to ingest those syslog events and adhere to ECS so it is possible to use Kibana Logs or SIEM more effectively. What happens is that the field "host" is used for the syslog events and "host.name" is used for elastic-agent events.

It seems like this problem might already be solved and I'm missing the obvious solution.

I have tried mutate { rename =\> { "host" =\> "host.name" }} but that throws the error of:

"Could not dynamically add mapping for field [host.name]. Existing mapping for [host] must be of type object but found [text]"

Help?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 2, 2021, 7:22pm UTC](https://discuss.elastic.co/t/logstash-syslog-ecs-and-kibana-logs-siem/274789/2 "2021-06-02T19:22:58Z")

</div>

Try

```
if [host] and ! [host][name] {
    mutate { rename => { "host" => "[host][name]" }}
}
```

---

<div class="post-metadata">

**Author:** ![egli](https://avatars.discourse-cdn.com/v4/letter/e/ed655f/32.png) [@egli](https://discuss.elastic.co/u/egli)\
**Post date:** [June 2, 2021, 9:30pm UTC](https://discuss.elastic.co/t/logstash-syslog-ecs-and-kibana-logs-siem/274789/3 "2021-06-02T21:30:00Z")

</div>

400 error with Elasticsearch:

"failed to parse field [host] of type [text] in document with id '...'. Preview of field's value: '{[name=example.com](http://name=example.com)}'", "caused\_by"=\>{"type"=\>"illegal\_state\_exception", "reason"="Can't get text on a START\_OBJECT at 1:45"}}}}}

[example.com](http://example.com) is the host sending the log to logstash.

It seems like the syslog- index created is totally different than the .ds-logs-system.syslog-default- index created by elastic-agent.

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [June 2, 2021, 9:32pm UTC](https://discuss.elastic.co/t/logstash-syslog-ecs-and-kibana-logs-siem/274789/4 "2021-06-02T21:32:30Z")

</div>

It looks like your index has [host] mapped as text, and not an object with a name field in it. Can you start over with a new index?

---

<div class="post-metadata">

**Author:** ![egli](https://avatars.discourse-cdn.com/v4/letter/e/ed655f/32.png) [@egli](https://discuss.elastic.co/u/egli)\
**Post date:** [June 2, 2021, 11:08pm UTC](https://discuss.elastic.co/t/logstash-syslog-ecs-and-kibana-logs-siem/274789/5 "2021-06-02T23:08:42Z")

</div>

I moved rsyslog and elastic-agent to the same host, the rsyslog server listening for incoming syslog. logstash as a syslog server was totally removed from the equation and all is good.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 30, 2021, 11:09pm UTC](https://discuss.elastic.co/t/logstash-syslog-ecs-and-kibana-logs-siem/274789/6 "2021-06-30T23:09:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
