# Logstash, syslog severity, etc

**URL:** <https://discuss.elastic.co/t/logstash-syslog-severity-etc/28057>\
**Category:** Logstash\
**Created:** [August 25, 2015, 9:56pm UTC](https://discuss.elastic.co/t/logstash-syslog-severity-etc/28057 "2015-08-25T21:56:43Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![declick](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/declick/32/4397_2.png) [@declick](https://discuss.elastic.co/u/declick)\
**Post date:** [August 25, 2015, 9:56pm UTC](https://discuss.elastic.co/t/logstash-syslog-severity-etc/28057/1 "2015-08-25T21:56:43Z")

</div>

I am a logstash noob, and have been trying to find the answer for a few hours now, searching here and all over google. Please forgive me if my question has been asked and answered - I'm starting to see double..

I have a Logstash/Elasticsearch/Kibana setup and running, and have my index configured, however - I am not able to determine why I don't see any of the syslog severity or facility codes. I am pretty sure its a grok filtering issue, but as I mentioned, I'm a noob, and I haven't figured it out yet.

Can someone point me in the right direction about a filter to use? I am using a pretty basic one now -

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [August 26, 2015, 6:06am UTC](https://discuss.elastic.co/t/logstash-syslog-severity-etc/28057/2 "2015-08-26T06:06:48Z")

</div>

Is the `syslog_pri` field set anywhere? That (configurable) field is used by the syslog\_pri filter to populate the facility and severity fields. You're not setting it in the grok filter so unless it's set by the input I don't know how this is supposed to work.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:30am UTC](https://discuss.elastic.co/t/logstash-syslog-severity-etc/28057/3 "2017-07-06T05:30:53Z")

</div>


