# Logstash syslog issue

**URL:** <https://discuss.elastic.co/t/logstash-syslog-issue/125383>\
**Category:** Logstash\
**Created:** [March 23, 2018, 2:49pm UTC](https://discuss.elastic.co/t/logstash-syslog-issue/125383 "2018-03-23T14:49:45Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![cybersecc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cybersecc/32/30979_2.png) [@cybersecc](https://discuss.elastic.co/u/cybersecc)\
**Post date:** [March 23, 2018, 2:49pm UTC](https://discuss.elastic.co/t/logstash-syslog-issue/125383/1 "2018-03-23T14:49:45Z")

</div>

Hello,  
I have configured a remote server to send syslog to logstash.. When I run tcpdump -Xni eth0 I can see that syslog packets are coming to logstash server, but in elasticsearch I see no results. By the way I read all related topic and tried all configs but no luck. I even tried to output to a file 😕 .. I've concluded that logstash input is the problem, here is my input conf:  
"""  
tcp {  
port =\> 5046  
type =\> syslog  
}  
udp {  
port =\> 5046  
type =\> syslog  
workers =\> 3  
queue\_size =\> 72000  
receive\_buffer\_bytes =\> 31457280  
}  
"""

Help is needed here

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 24, 2018, 8:03am UTC](https://discuss.elastic.co/t/logstash-syslog-issue/125383/2 "2018-03-24T08:03:40Z")

</div>

How have you concluded that the input is the problem? It looks OK as far as I can see.

---

<div class="post-metadata">

**Author:** ![cybersecc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cybersecc/32/30979_2.png) [@cybersecc](https://discuss.elastic.co/u/cybersecc)\
**Post date:** [March 26, 2018, 8:19am UTC](https://discuss.elastic.co/t/logstash-syslog-issue/125383/3 "2018-03-26T08:19:46Z")

</div>

I have run tcpdump and packets are coming from the remote syslog, but I can see nothing in elasticsearch, I tried ti output to a file but nothing

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 26, 2018, 8:21am UTC](https://discuss.elastic.co/t/logstash-syslog-issue/125383/4 "2018-03-26T08:21:39Z")

</div>

What does the rest of your Logstash config look like? Have you tried outputting to a `stdou`t plugin with a `rubydebug` codec to what is actually being processed? have you tried to increase the Logstash logging level to debug to see if there are any errors reported?

---

<div class="post-metadata">

**Author:** ![cybersecc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cybersecc/32/30979_2.png) [@cybersecc](https://discuss.elastic.co/u/cybersecc)\
**Post date:** [March 26, 2018, 8:23am UTC](https://discuss.elastic.co/t/logstash-syslog-issue/125383/5 "2018-03-26T08:23:51Z")

</div>

```
elasticsearch {
    hosts => ["elasticsearch"]
    index => "syslog-%{+YYYY-MM-dd}"
    document_id => "%{@uuid}"
}

```

this is my output. I do not use rubydebug can you guide me through?

---

<div class="post-metadata">

**Author:** ![Christian\_Dahlqvist](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/christian_dahlqvist/32/4617_2.png) [@Christian\_Dahlqvist](https://discuss.elastic.co/u/Christian_Dahlqvist)\
**Post date:** [March 26, 2018, 8:31am UTC](https://discuss.elastic.co/t/logstash-syslog-issue/125383/6 "2018-03-26T08:31:57Z")

</div>

Add this to the output section:

```auto
stdout {
  codec => rubydebug
}

```

What about the rest of the config? Where does the `uuid` come from?

Do you see anything in the logs?

---

<div class="post-metadata">

**Author:** ![cybersecc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cybersecc/32/30979_2.png) [@cybersecc](https://discuss.elastic.co/u/cybersecc)\
**Post date:** [March 26, 2018, 8:57am UTC](https://discuss.elastic.co/t/logstash-syslog-issue/125383/7 "2018-03-26T08:57:57Z")

</div>

this is logstash's log  
[2018-03-23T14:16:45,927][INFO][logstash.inputs.udp] UDP listener started {:address=\>"0.0.0.0:5046", :receive\_buffer\_bytes=\>"31457280", :queue\_size=\>"72000"}

rubydebug: All I see is other logs in the output but I see nothing related to syslog also there is no error. (My logstash is on a docker container so I used this cmd: sudo docker logs -f logstash\_1), plz correct me if I'm wrong.

I must say that in my elastic I can see IDS, vuln scanner logs, and even docker syslog

---

<div class="post-metadata">

**Author:** ![rcowart](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rcowart/32/88091_2.png) [@rcowart](https://discuss.elastic.co/u/rcowart)\
**Post date:** [March 26, 2018, 9:36am UTC](https://discuss.elastic.co/t/logstash-syslog-issue/125383/8 "2018-03-26T09:36:28Z")

</div>

Make sure that the incoming data is not blocked by a local firewall. On Linux tcpdump see packets before they are evaluated by the firewall.

---

<div class="post-metadata">

**Author:** ![cybersecc](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/cybersecc/32/30979_2.png) [@cybersecc](https://discuss.elastic.co/u/cybersecc)\
**Post date:** [March 26, 2018, 10:11am UTC](https://discuss.elastic.co/t/logstash-syslog-issue/125383/9 "2018-03-26T10:11:23Z")

</div>

> [@rcowart](#):
>
> Make sure that the incoming data is not

no problems with firewall I enabled the port

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [April 23, 2018, 10:11am UTC](https://discuss.elastic.co/t/logstash-syslog-issue/125383/10 "2018-04-23T10:11:43Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
