# Logstash syslog output: Weird message processing

**URL:** <https://discuss.elastic.co/t/logstash-syslog-output-weird-message-processing/207838>\
**Category:** Logstash\
**Created:** [November 14, 2019, 8:51am UTC](https://discuss.elastic.co/t/logstash-syslog-output-weird-message-processing/207838 "2019-11-14T08:51:53Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![froto](https://avatars.discourse-cdn.com/v4/letter/f/85f322/32.png) [@froto](https://discuss.elastic.co/u/froto)\
**Post date:** [November 14, 2019, 8:51am UTC](https://discuss.elastic.co/t/logstash-syslog-output-weird-message-processing/207838/1 "2019-11-14T08:51:53Z")

</div>

Hey there!

I've been trying to send a part of my events to another syslog receiver for further processing.

I use the logstash-output-syslog plugin for this purpose.

This is my configuration:

```
> output {
> if "flow" in [tags] {
> syslog {
> host => ["127.0.0.1"]
> port => 515
> message => "from:%{[flow][src_addr]} to %{[flow][dst_addr]} src_addr_locality=%{[flow][src_addr_locality]} dst_addr_locality=%{[flow][dst_addr_locality]} dst_port=%{[flow][dst_port]}"
> }
> }
> }

```

All these fields definitely exist!

If I filter the logstash output via tcpdump I only get the following message:

`<13>Nov 14 08:39:46 %{host} LOGSTASH[-]: 2019-11-14T08:39:46.976Z %{host} %{message}`

Does anyone have a idea why the event contains the value "%{message}" and not the configured string ?

(I am using Logstash-OSS 7.3.1 and the latest syslog output plugin)

---

<div class="post-metadata">

**Author:** ![iridescent233](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iridescent233/32/57651_2.png) [@iridescent233](https://discuss.elastic.co/u/iridescent233)\
**Post date:** [November 14, 2019, 9:17am UTC](https://discuss.elastic.co/t/logstash-syslog-output-weird-message-processing/207838/2 "2019-11-14T09:17:56Z")

</div>

Change the part of message =\> "" to  
codec =\> plain {  
format =\> "from:%{[flow][src\_addr]} to %{[flow][dst\_addr]} src\_addr\_locality=%{[flow][src\_addr\_locality]} dst\_addr\_locality=%{[flow][dst\_addr\_locality]} dst\_port=%{[flow][dst\_port]}"  
}

---

<div class="post-metadata">

**Author:** ![iridescent233](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/iridescent233/32/57651_2.png) [@iridescent233](https://discuss.elastic.co/u/iridescent233)\
**Post date:** [November 14, 2019, 9:29am UTC](https://discuss.elastic.co/t/logstash-syslog-output-weird-message-processing/207838/3 "2019-11-14T09:29:05Z")

</div>

You can also modify the source code of the logstash-output-syslog plugin to define it in whatever format you want.it‘s so easy.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 12, 2019, 9:29am UTC](https://discuss.elastic.co/t/logstash-syslog-output-weird-message-processing/207838/4 "2019-12-12T09:29:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
