# Multiple Syslog Sources Configuration on Single Elastic Agent Port, port 514

**URL:** <https://discuss.elastic.co/t/multiple-syslog-sources-configuration-on-single-elastic-agent-port-port-514/375109>\
**Category:** Elastic Agent\
**Created:** [February 26, 2025, 10:02pm UTC](https://discuss.elastic.co/t/multiple-syslog-sources-configuration-on-single-elastic-agent-port-port-514/375109 "2025-02-26T22:02:02Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![IsaacZhu](https://avatars.discourse-cdn.com/v4/letter/i/df705f/32.png) [@IsaacZhu](https://discuss.elastic.co/u/IsaacZhu)\
**Post date:** [February 26, 2025, 10:02pm UTC](https://discuss.elastic.co/t/multiple-syslog-sources-configuration-on-single-elastic-agent-port-port-514/375109/1 "2025-02-26T22:02:02Z")

</div>

Current Setup:

- Elastic Agent collecting syslog messages from:
  - Aruba access points and switches (Custom UDP integration)
  - F5 VPN (Custom UDP integration)
  - Fortigate firewalls (Fortigate Syslog integration)

- All configured to use port 514
- Single Elastic Agent instance

Issue:  
All syslog messages are being processed only by the Fortigate Syslog integration, while the custom UDP integrations for Aruba and F5 are being bypassed completely.

Question:  
What's the recommended approach to configure multiple syslog sources (Aruba, F5, Fortigate) on a single Elastic Agent using the same port (514)? Looking for a solution that doesn't require setting up different ports for each system.

Additional Context:

- Need to maintain standard syslog port (514)
- Prefer to keep single agent configuration
- Require proper message routing to respective integrations

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 26, 2025, 10:31pm UTC](https://discuss.elastic.co/t/multiple-syslog-sources-configuration-on-single-elastic-agent-port-port-514/375109/2 "2025-02-26T22:31:01Z")

</div>

Hello and welcome,

You cannot have multiple integrations listening on the same port, each integration is a different process and you cannot bind different processes to the same port.

It is required to use a different port for each integration.

If you cannot change the port and need to use 514 you need something to reroute the events to the correct integration.

Depending on the version of the stack you are, there is a new integration called [Syslog Router](https://www.elastic.co/guide/en/integrations/current/syslog_router.html) that can do that, it has some pre-configured patterns to reroute to the correct integration, but you can also add extra patterns. This integration requires version 8.14.3 or higher and it is still in beta.

You can also do this reroute using `rsyslog`, in this case you would need to configure each integration with a different internal port and in rsyslog you could direct the logs to each integration based on the source or some other logic.

---

<div class="post-metadata">

**Author:** ![IsaacZhu](https://avatars.discourse-cdn.com/v4/letter/i/df705f/32.png) [@IsaacZhu](https://discuss.elastic.co/u/IsaacZhu)\
**Post date:** [February 26, 2025, 11:33pm UTC](https://discuss.elastic.co/t/multiple-syslog-sources-configuration-on-single-elastic-agent-port-port-514/375109/3 "2025-02-26T23:33:35Z")

</div>

Thanks Leandro, that's very helpful! I'm wondering if I have these integrations on different agent instances but still with the same port, so essentially I'm gonna switch to a multi-agent setup, will it solve this problem?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 27, 2025, 12:24am UTC](https://discuss.elastic.co/t/multiple-syslog-sources-configuration-on-single-elastic-agent-port-port-514/375109/4 "2025-02-27T00:24:48Z")

</div>

> [@IsaacZhu](#):
>
> I'm wondering if I have these integrations on different agent instances but still with the same port, so essentially I'm gonna switch to a multi-agent setup, will it solve this problem?

If by different instances you mean completely different machines/VMs, then you will have no issues as the agents would be running on different places.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [February 27, 2025, 12:30am UTC](https://discuss.elastic.co/t/multiple-syslog-sources-configuration-on-single-elastic-agent-port-port-514/375109/5 "2025-02-27T00:30:59Z")

</div>

Also, are you using Fleet Managed or Standalone agents?

If you are using Fleet Managed, you would need one policy per agent.

---

<div class="post-metadata">

**Author:** ![IsaacZhu](https://avatars.discourse-cdn.com/v4/letter/i/df705f/32.png) [@IsaacZhu](https://discuss.elastic.co/u/IsaacZhu)\
**Post date:** [February 27, 2025, 12:47am UTC](https://discuss.elastic.co/t/multiple-syslog-sources-configuration-on-single-elastic-agent-port-port-514/375109/6 "2025-02-27T00:47:01Z")

</div>

Yes, that's great to hear. Exactly, I mean by different VMs.

---

<div class="post-metadata">

**Author:** ![IsaacZhu](https://avatars.discourse-cdn.com/v4/letter/i/df705f/32.png) [@IsaacZhu](https://discuss.elastic.co/u/IsaacZhu)\
**Post date:** [February 27, 2025, 12:47am UTC](https://discuss.elastic.co/t/multiple-syslog-sources-configuration-on-single-elastic-agent-port-port-514/375109/7 "2025-02-27T00:47:45Z")

</div>

It's standalone agents
