# Minimal filebeat config: syslog -\> file

**URL:** <https://discuss.elastic.co/t/minimal-filebeat-config-syslog-file/138968>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [July 6, 2018, 5:42pm UTC](https://discuss.elastic.co/t/minimal-filebeat-config-syslog-file/138968 "2018-07-06T17:42:58Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Magnus\_Therning](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_therning/32/33091_2.png) [@Magnus\_Therning](https://discuss.elastic.co/u/Magnus_Therning)\
**Post date:** [July 6, 2018, 5:42pm UTC](https://discuss.elastic.co/t/minimal-filebeat-config-syslog-file/138968/1 "2018-07-06T17:42:58Z")

</div>

In an attempt to walk before running I thought I'd set up a _filebeat_ instance as a syslog server and then use `logger` to send log messages to it.

My Docker Compose configuration for setting up _filebeat_ is

```
filebeat:
  image: docker.elastic.co/beats/filebeat:6.3.1
  stdin_open: true
  tty: true
  command: filebeat -v -c /config-dir/filebeat.yml
  restart: always
  ports:
    - "5000:5000"
  volumes:
    - ./log-cfg/filebeat.yml:/config-dir/filebeat.yml
    - ./beat-out/:/beat-out/

```

The file `filebeat.yml` contains

```
filebeat.inputs:
  - type: syslog
    protocol.tcp.host: "localhost:5000"

output.file.path: "/beat-out"

logging:
  level: debug
  to_files: true

```

Bringing up _filebeat_ with `docker-compose up filebeat` succeeds. And sending log messages using `logger --server localhost --port 5000 --tcp --rfc3164 "An error"` succeeds too. However, there is nothing printed to any file in `./beat-out/`.

Attaching to the running instance and inspecting the log (`/usr/share/filebeat/logs/filebeat`) doesn't help me understand what's missing. A log can be found at [http://ix.io/1gdq](http://ix.io/1gdq). Also, nothing appears in the _filebeat_ log when sending a syslog message with `logger`.

What am I missing here?

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [July 6, 2018, 7:37pm UTC](https://discuss.elastic.co/t/minimal-filebeat-config-syslog-file/138968/2 "2018-07-06T19:37:41Z")

</div>

> [@Magnus\_Therning](#):
>
> protocol.tcp.host: "localhost:5000"

The syslog input is being bound to the container's loopback interface. Just need to remove the host name:

> protocol.tcp.host: ":5000"

---

<div class="post-metadata">

**Author:** ![Magnus\_Therning](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnus_therning/32/33091_2.png) [@Magnus\_Therning](https://discuss.elastic.co/u/Magnus_Therning)\
**Post date:** [July 6, 2018, 9:12pm UTC](https://discuss.elastic.co/t/minimal-filebeat-config-syslog-file/138968/3 "2018-07-06T21:12:13Z")

</div>

Indeed! Thanks!

I do wonder what answered `logger` when it tried to connect to port 5000 locally...

---

<div class="post-metadata">

**Author:** ![adrisr](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/adrisr/32/25423_2.png) [@adrisr](https://discuss.elastic.co/u/adrisr)\
**Post date:** [July 9, 2018, 9:07am UTC](https://discuss.elastic.co/t/minimal-filebeat-config-syslog-file/138968/4 "2018-07-09T09:07:10Z")

</div>

> [@Magnus\_Therning](#):
>
> I do wonder what answered `logger` when it tried to connect to port 5000 locally...

That was docker itself. If you try to connect to a bound port that is closed inside the container, docker will still accept the connection and then close it immediately.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2018, 9:07am UTC](https://discuss.elastic.co/t/minimal-filebeat-config-syslog-file/138968/5 "2018-08-06T09:07:10Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
