# Logstash with syslog input doesn't send logs to Elasticsearch

**URL:** https://discuss.elastic.co/t/logstash-with-syslog-input-doesnt-send-logs-to-elasticsearch/238553
**Category:** Logstash
**Tags:** elastic-stack-security
**Created:** [June 24, 2020, 7:43pm UTC](https://discuss.elastic.co/t/logstash-with-syslog-input-doesnt-send-logs-to-elasticsearch/238553 "2020-06-24T19:43:20Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![jelocabral](https://avatars.discourse-cdn.com/v4/letter/j/e0b2c6/32.png) [@jelocabral](https://discuss.elastic.co/u/jelocabral)
#### Post date: [June 24, 2020, 7:43pm UTC](https://discuss.elastic.co/t/logstash-with-syslog-input-doesnt-send-logs-to-elasticsearch/238553/1 "2020-06-24T19:43:20Z")

</div>

Dear, I've configured Logstash 7.8.0 with a Syslog input, into an index called "syslog-514-xxxxx":

input {  
udp {  
port =\> 514  
type =\> syslog  
}  
}

output {  
elasticsearch {  
hosts =\> ["[https://172.31.2.2:9200](https://172.31.2.2:9200)" ]  
user =\> "elastic"  
password =\> "xxx"  
ssl =\> true  
cacert =\> "/etc/ssl/certs/ca.crt"  
manage\_template =\> false  
index =\> "syslog-514-%{+YYYY.MM.dd}"  
}  
}

If I execute tcpdumpo in ELK server, I can see logs coming from a rsyslog client to my UDP/514 port.

But if I execute tcpdump to view logs passing from port UDP/514 to port TCP/9200 (Elasticsearch 7.8.0), I can't see any traffic at all.

What can be the problem ?

The index syslog-514-xxxxx is populated by data, I can see this in the index management tab.

And also, how should I see the logs in Kibana? Where should I have to look for them?

Thanks in advance!!!

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 22, 2020, 7:43pm UTC](https://discuss.elastic.co/t/logstash-with-syslog-input-doesnt-send-logs-to-elasticsearch/238553/2 "2020-07-22T19:43:27Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
