# Logstash writing logs to syslog even though no output configured

**URL:** <https://discuss.elastic.co/t/logstash-writing-logs-to-syslog-even-though-no-output-configured/167428>\
**Category:** Logstash\
**Created:** [February 7, 2019, 11:01am UTC](https://discuss.elastic.co/t/logstash-writing-logs-to-syslog-even-though-no-output-configured/167428 "2019-02-07T11:01:17Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![commentator8](https://avatars.discourse-cdn.com/v4/letter/c/f08c70/32.png) [@commentator8](https://discuss.elastic.co/u/commentator8)\
**Post date:** [February 7, 2019, 11:01am UTC](https://discuss.elastic.co/t/logstash-writing-logs-to-syslog-even-though-no-output-configured/167428/1 "2019-02-07T11:01:17Z")

</div>

Hi,

I am trying to understand how it is that my logstash instance is writing logs to /var/log/syslog.  
I have debug open and it fills up my 40gb hard drive within hours.

I checked that the contents of /etc/rsyslog.d/50-default.conf and /etc/rsyslog.conf are the same as other servers, and i can't for the life of me understand how to prevent this.

Logs are in the format:  
Feb 7 12:50:43 eq-svc06 logstash[12597]: [2019-02-07T12:50:43,088][DEBUG][org.logstash.beats.BeatsHandler] [local: 192.168.100.46:5044, remote: 192.168.100.198:51814] Sending a new message for the listener, sequence: 6

I have only one output open which is elasticsearch (same box). Just to confirm:

root@eq-svc06:~# grep -r "output" /etc/logstash/  
/etc/logstash/logstash.yml:# Set the number of workers that will, in parallel, execute the filters+outputs  
/etc/logstash/logstash.yml:# before dispatching an undersized batch to filters+outputs  
/etc/logstash/logstash.yml:# received events have been pushed to the outputs.  
/etc/logstash/logstash.yml.dpkg-dist:# Set the number of workers that will, in parallel, execute the filters+outputs  
/etc/logstash/logstash.yml.dpkg-dist:# before dispatching an undersized batch to filters+outputs  
/etc/logstash/logstash.yml.dpkg-dist:# received events have been pushed to the outputs.  
/etc/logstash/logstash-sample.conf:output {  
/etc/logstash/cert/custom\_openssl.cnf:# output\_password = secret  
/etc/logstash/conf.d/output\_beats.conf:output {

root@eq-svc06:~# grep -r "syslog" /etc/logstash/  
/etc/logstash/conf.d/filter\_system.conf: } else if [fileset][name] == "syslog" {  
/etc/logstash/conf.d/filter\_system.conf: id =\> "system\_syslog"  
/etc/logstash/conf.d/filter\_system.conf: "message" =\> ["%{SYSLOGTIMESTAMP:[system][syslog][timestamp]} %{SYSLOGHOST:[system][syslog][hostname]} %{DATA:[system][syslog][program]}(?:[%{POSINT:[system][syslog][pid]}])?: %{GREEDYMULTILINE:[system][syslog][message]}"]  
/etc/logstash/conf.d/filter\_system.conf: match =\> ["[system][syslog][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
/etc/logstash/conf.d/filter\_system.conf: "category" =\> "system\_syslog"

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 7, 2019, 11:01am UTC](https://discuss.elastic.co/t/logstash-writing-logs-to-syslog-even-though-no-output-configured/167428/2 "2019-03-07T11:01:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
