# Logstash syslog output format

**URL:** <https://discuss.elastic.co/t/logstash-syslog-output-format/185834>\
**Category:** Logstash\
**Created:** [June 14, 2019, 10:27am UTC](https://discuss.elastic.co/t/logstash-syslog-output-format/185834 "2019-06-14T10:27:51Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![vld53](https://avatars.discourse-cdn.com/v4/letter/v/8e7dd6/32.png) [@vld53](https://discuss.elastic.co/u/vld53)\
**Post date:** [June 14, 2019, 10:27am UTC](https://discuss.elastic.co/t/logstash-syslog-output-format/185834/1 "2019-06-14T10:27:51Z")

</div>

Hello guys!  
I have question about syslog output plugin.

Configuration:

```
output {                             
  if "mail" in [tags] {
     	syslog {
              facility => "local0"
              host => "192.168.0.3"
              port => "514"
              severity => "informational"
              protocol => "udp"
                      }

```

Output result:  
`Jun 14 10:23:07 ls09 %{host} LOGSTASH[]: *mail log*`

How can i delete "`Jun 14 10:23:07 ls09 %{host} LOGSTASH[]:` " part of syslog output? And just send by syslog `*mail log*` messages?

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [June 14, 2019, 10:55am UTC](https://discuss.elastic.co/t/logstash-syslog-output-format/185834/2 "2019-06-14T10:55:53Z")

</div>

Why are you using syslog output if you don't want syslog format?  
You can just use udp output instead.

If you want to insist on using syslog output for some reason, I guess you can define the codec as line and change the formatting.

---

<div class="post-metadata">

**Author:** ![vld53](https://avatars.discourse-cdn.com/v4/letter/v/8e7dd6/32.png) [@vld53](https://discuss.elastic.co/u/vld53)\
**Post date:** [June 14, 2019, 11:30am UTC](https://discuss.elastic.co/t/logstash-syslog-output-format/185834/3 "2019-06-14T11:30:51Z")

</div>

Just because `*mail log*` is that `"Jun 14 14:27:42 mail46 postfix/smtpd[43252]: disconnect from pc1[192.168.0.7]"`

And I want to send just only `*mail log*` like syslog message without `Jun 14 10:23:07 ls09 %{host} LOGSTASH[]:`

Now i have follow `Jun 14 10:23:07 ls09 %{host} LOGSTASH[]: Jun 14 14:27:42 mail46 postfix/smtpd[43252]: disconnect from pc1[192.168.0.7]`

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [June 14, 2019, 11:32am UTC](https://discuss.elastic.co/t/logstash-syslog-output-format/185834/4 "2019-06-14T11:32:05Z")

</div>

That didn't answer the question.

If you don't want syslog headers but only the message part, you are better off using either udp or tcp output plugin.

EDIT: Maybe I misunderstood. So you are saying you get double headers?

---

<div class="post-metadata">

**Author:** ![vld53](https://avatars.discourse-cdn.com/v4/letter/v/8e7dd6/32.png) [@vld53](https://discuss.elastic.co/u/vld53)\
**Post date:** [June 14, 2019, 11:34am UTC](https://discuss.elastic.co/t/logstash-syslog-output-format/185834/5 "2019-06-14T11:34:59Z")

</div>

> If you don't want syslog headers but only the message part, you are better off using either udp or tcp output plugin.

Yes, I catch your thought.

> So you are saying you get double headers?

Yes. If I use syslog I have double headers one of LS other of my mail log... Can I use only mail log headers in my syslog message?

---

<div class="post-metadata">

**Author:** ![admlko](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/admlko/32/21787_2.png) [@admlko](https://discuss.elastic.co/u/admlko)\
**Post date:** [June 14, 2019, 11:36am UTC](https://discuss.elastic.co/t/logstash-syslog-output-format/185834/6 "2019-06-14T11:36:23Z")

</div>

If you want to preserve original headers, ditch the syslog output and use udp or tcp output as I said.

If you want to get rid of original header and generate new one, you have to parse the old header away - for example with grok - and use syslog output.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 12, 2019, 11:36am UTC](https://discuss.elastic.co/t/logstash-syslog-output-format/185834/7 "2019-07-12T11:36:25Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
