# Logstash syslog UDP output

**URL:** <https://discuss.elastic.co/t/logstash-syslog-udp-output/202698>\
**Category:** Logstash\
**Created:** [October 8, 2019, 3:39pm UTC](https://discuss.elastic.co/t/logstash-syslog-udp-output/202698 "2019-10-08T15:39:49Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![toosaman](https://avatars.discourse-cdn.com/v4/letter/t/d78d45/32.png) [@toosaman](https://discuss.elastic.co/u/toosaman)\
**Post date:** [October 8, 2019, 3:39pm UTC](https://discuss.elastic.co/t/logstash-syslog-udp-output/202698/1 "2019-10-08T15:39:50Z")

</div>

Hello. I'm trying to forward syslog messages to my ES cluster and UDP output to external server at the same time. But, for UDP output I don't want to change its contents. For example: now, logstash insert timestamp field and remove facility:

input message:

**USER.LOCAL**  
**2019-10-08T14:49:46Z HOST storageRM[5591140]: KB-IT-Store, 0**

output message:

**2019-10-08T14:50:57.228Z X.X.X.X. \<13\>2019-10-08T14:50:57Z HOST storageRM[5591140]: KB-IT-Store, 0**

Logstash config:

input {  
udp {  
port =\> 1514  
type =\> syslog  
id =\> "syslog\_udp"  
}  
}  
output {  
if [type] == "syslog" {  
pipeline {  
send\_to =\> syslog\_pipe  
}  
udp {  
host =\> "10.x.x.x"  
port =\> "514"  
codec =\> "plain"  
}

How can I do that?  
Thanks!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 5, 2019, 3:39pm UTC](https://discuss.elastic.co/t/logstash-syslog-udp-output/202698/2 "2019-11-05T15:39:55Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
