# Logstash syslog rfc 5424 and rfc 3164 input

**URL:** <https://discuss.elastic.co/t/logstash-syslog-rfc-5424-and-rfc-3164-input/180520>\
**Category:** Logstash\
**Created:** [May 10, 2019, 9:04am UTC](https://discuss.elastic.co/t/logstash-syslog-rfc-5424-and-rfc-3164-input/180520 "2019-05-10T09:04:20Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![mkain](https://avatars.discourse-cdn.com/v4/letter/m/ba8739/32.png) [@mkain](https://discuss.elastic.co/u/mkain)\
**Post date:** [May 10, 2019, 9:04am UTC](https://discuss.elastic.co/t/logstash-syslog-rfc-5424-and-rfc-3164-input/180520/1 "2019-05-10T09:04:20Z")

</div>

Hi,

`I want to handle syslogs of both RFC in ELK 6.7. So far my working config is:`

```
input {
    tcp {
            port => 514
            type => syslog
    }
    udp {
            port => 514
            type => syslog
    }
}

filter {
    if [type] == "syslog" {
            grok {
            match => {
                    "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}"
                    }
    add_field => ["received_from", "%{host}"]
            }
    }
}

output {
    elasticsearch {
    hosts => ["127.0.0.1:9200"]
    }
    stdout {
            codec => rubydebug
    }
}

```

And with this I get \_grokparsefailure error while processing many syslog messages. I think above config is just handling RFC 3164.

Can someone please guide me how can I handle rfc 5424 and rfc 3164 message parsing in logstash ?

Regards,  
-Manish

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [June 7, 2019, 9:04am UTC](https://discuss.elastic.co/t/logstash-syslog-rfc-5424-and-rfc-3164-input/180520/2 "2019-06-07T09:04:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
