# Logstash - syslog output

**URL:** <https://discuss.elastic.co/t/logstash-syslog-output/305288>\
**Category:** Logstash\
**Created:** [May 20, 2022, 11:54am UTC](https://discuss.elastic.co/t/logstash-syslog-output/305288 "2022-05-20T11:54:52Z")\
**Posts on this page:** 10\
**Page:** 1

<div class="post-metadata">

**Author:** ![humartinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/humartinez/32/46395_2.png) [@humartinez](https://discuss.elastic.co/u/humartinez)\
**Post date:** [May 20, 2022, 11:54am UTC](https://discuss.elastic.co/t/logstash-syslog-output/305288/1 "2022-05-20T11:54:52Z")

</div>

Hi,  
Im with some issues configuring the output to syslog. It may be some syntax that Im unaware of, but I can't use my document field values to map some of the plugin output fields.

Im trying to use one of my records fields in order to use with the syslog output plugin (according to the documentation of the plugin) and logstash is unable to write the value of the field instead it s writes the name of the field as literal.

Here is my config and output that the syslog is getting

```auto
    # all input will come from filebeat, no local logs
    input {
      beats {
        port => 5074
      }
    }

    filter {
      json {
        source => "message"
      }
      if [audit_log] and [audit_log][0] {
         split {
           field => "audit_log"
         }
         mutate {
           remove_field => ["message"]
        }
       } else {
           drop { }
       }

    }

    output {
      syslog {
        host => "my_syslog_host"
        port => 514
        protocol => "udp"
        appname => "%{log_type}"
        message => "%{audit_log}"
      }
    }

```

```auto
May 20 10:16:39 10-213-123-179 {"name":"filebeat-audit-mongodb-547c49bf4d-zpmfd"} %{[log_type]}[-]: 2022-05-20T10:16:39.594Z {name=filebeat-audit-mongodb-547c49bf4d-zpmfd} %{message}
May 20 10:16:39 10-213-123-179 {"name":"filebeat-audit-mongodb-547c49bf4d-zpmfd"} %{[log_type]}[-]: 2022-05-20T10:16:39.594Z {name=filebeat-audit-mongodb-547c49bf4d-zpmfd} %{message}
May 20 10:31:43 10-213-123-179 {"name":"filebeat-audit-mongodb-547c49bf4d-zpmfd"} %{[log_type]}[-]: 2022-05-20T10:31:43.545Z {name=filebeat-audit-mongodb-547c49bf4d-zpmfd} %{message}
May 20 10:31:43 10-213-123-179 {"name":"filebeat-audit-mongodb-547c49bf4d-zpmfd"} %{[log_type]}[-]: 2022-05-20T10:31:43.545Z {name=filebeat-audit-mongodb-547c49bf4d-zpmfd} %{message}

```

As a workarround I renamed the field audit\_log to message, but If I want to change the value of the appname , severity or whatever, the notation "%{foo}" do not work.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 20, 2022, 12:37pm UTC](https://discuss.elastic.co/t/logstash-syslog-output/305288/2 "2022-05-20T12:37:42Z")

</div>

When you have the literal value of the field like `%{field_name}` this normally indicates that the field does not exist in the document.

I do not see anything wrong in the output configuration.

Can you add a `stdout` output and share the document that is being created in the output block?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [May 20, 2022, 5:23pm UTC](https://discuss.elastic.co/t/logstash-syslog-output/305288/3 "2022-05-20T17:23:39Z")

</div>

> [@humartinez](#):
>
> ```auto
> if [audit_log] and [audit_log][0] {
> split {
> 
> ```

You are only splitting this field if it is already an array. Is that really what you want?

As Leandro says, the appearance of %{[log\_type]} in the output means that field does not exist, since the code does [sprintf](https://github.com/logstash-plugins/logstash-output-syslog/blob/30b8f9130878595ab87dfa0fbd4b8f04b0ed7139/lib/logstash/outputs/syslog.rb#L151) the option.

---

<div class="post-metadata">

**Author:** ![humartinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/humartinez/32/46395_2.png) [@humartinez](https://discuss.elastic.co/u/humartinez)\
**Post date:** [May 23, 2022, 6:23am UTC](https://discuss.elastic.co/t/logstash-syslog-output/305288/4 "2022-05-23T06:23:04Z")

</div>

Guys,  
The field exist, here is a sample of my doc

 ![Captura de pantalla 2022-05-23 082007](https://us1.discourse-cdn.com/elastic/original/3X/6/6/66e5cb0f16c794eba1fcf4e7b53fe1eb4b5b3de3.png)

Also @Badger the conditional is to drop events in which the array audit\_log is empty

---

<div class="post-metadata">

**Author:** ![humartinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/humartinez/32/46395_2.png) [@humartinez](https://discuss.elastic.co/u/humartinez)\
**Post date:** [May 23, 2022, 12:20pm UTC](https://discuss.elastic.co/t/logstash-syslog-output/305288/5 "2022-05-23T12:20:53Z")

</div>

@leandrojmp the most anoying is appname, and the field that I need to put ther is log\_type, the message string I work arround it by renaming the field audit\_log to message.

I changed my config to

```auto
    output {
      syslog {
        host => "rsyslog.monitoring.svc.cluster.local"
        port => 5514
        protocol => "udp"
        appname => "logstash.%{log_type}"
      }
    }

```

rsyslog output

```auto
May 23 12:40:37 10-213-162-57 {"name":"filebeat-audit-mongodb-547c49bf4d-gh52h"} logstash.%{log_type}[-]: 2022-05-23T12:40:37.640Z .....

```

And I still can't read the field _log\_type_

---

<div class="post-metadata">

**Author:** ![humartinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/humartinez/32/46395_2.png) [@humartinez](https://discuss.elastic.co/u/humartinez)\
**Post date:** [May 24, 2022, 7:05am UTC](https://discuss.elastic.co/t/logstash-syslog-output/305288/6 "2022-05-24T07:05:29Z")

</div>

Could someone give me another clue about this issue?

---

<div class="post-metadata">

**Author:** ![humartinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/humartinez/32/46395_2.png) [@humartinez](https://discuss.elastic.co/u/humartinez)\
**Post date:** [May 25, 2022, 2:14pm UTC](https://discuss.elastic.co/t/logstash-syslog-output/305288/7 "2022-05-25T14:14:43Z")

</div>

If someone is so kind to help me it would be appreciated

---

<div class="post-metadata">

**Author:** ![humartinez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/humartinez/32/46395_2.png) [@humartinez](https://discuss.elastic.co/u/humartinez)\
**Post date:** [May 31, 2022, 10:57am UTC](https://discuss.elastic.co/t/logstash-syslog-output/305288/8 "2022-05-31T10:57:55Z")

</div>

any clue?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [May 31, 2022, 12:33pm UTC](https://discuss.elastic.co/t/logstash-syslog-output/305288/9 "2022-05-31T12:33:53Z")

</div>

> [@leandrojmp](#):
>
> Can you add a `stdout` output and share the document that is being created in the output block?

Can you provide this in plain text?

As already said before, the existence of `%{log_type}` indicates that the field does not exist.

Try to set a file output to test what is passing through logstash, and also set the `stdout` output.

For example:

```auto
output {
    file {
        path => "/tmp/test-output.log"
        codec => line { format => "%{log_type} - %{audit_log} - %{message}" }
    }
    syslog { your syslog output }
   stdout {}
}

```

This part of the [code](https://github.com/logstash-plugins/logstash-output-syslog/blob/30b8f9130878595ab87dfa0fbd4b8f04b0ed7139/lib/logstash/outputs/syslog.rb#L150-L153) in the syslog output is pretty simple, if the field exists, it will sprintf to get the value.

Does this happens for every message or just some?

Can you track the **same** message and share how it appears in the source file before being read by filebeat, and in the logstash outputs of syslog, file and stdout? Also, do not remove the message field until you figure out what is the issue, being able to see the original message field can help in the troubleshooting process.

If the field really exists, but the syslog output is not making a sprintf to get its value, then it could be a bug and you will need to open an issue in the [repository](https://github.com/logstash-plugins/logstash-output-syslog).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 28, 2022, 12:34pm UTC](https://discuss.elastic.co/t/logstash-syslog-output/305288/10 "2022-06-28T12:34:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
