# Need help in listing syslog data (10000 +)

**URL:** https://discuss.elastic.co/t/need-help-in-listing-syslog-data-10000/242902
**Category:** Kibana
**Created:** [July 28, 2020, 12:27pm UTC](https://discuss.elastic.co/t/need-help-in-listing-syslog-data-10000/242902 "2020-07-28T12:27:09Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![nisaxena](https://avatars.discourse-cdn.com/v4/letter/n/ebca7d/32.png) [@nisaxena](https://discuss.elastic.co/u/nisaxena)
#### Post date: [July 28, 2020, 12:27pm UTC](https://discuss.elastic.co/t/need-help-in-listing-syslog-data-10000/242902/1 "2020-07-28T12:27:09Z")

</div>

Hi There,

I am new to ELK and need help. I am working on syslog data collected from all zonal rsyslog servers. Now I am putting some visualization to this data. there are around 10000+ unique hosts data collected everyday.  
Now, I wish to create a dashboard to keep a track of

a. List of hosts reported their logs everyday .... I am able to plot it but in numbers .. how can I get the list of hosts ?  
b. I also wish to pull the list of hosts not reported their logs and/or the list of extra hosts reported their logs ?

Thanks,  
Nitin

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [July 28, 2020, 10:26pm UTC](https://discuss.elastic.co/t/need-help-in-listing-syslog-data-10000/242902/2 "2020-07-28T22:26:19Z")

</div>

That's a lot of hosts to just list out in a big table. Given you want to also show hosts that haven't reported, why do you need the list of ones that have?

For the missing hosts, you can use Alerting and then [something like this](https://github.com/elastic/examples/tree/master/Alerting/Sample%20Watches/system_fails_to_provide_data).

---

<div class="post-metadata">

### Author: ![nisaxena](https://avatars.discourse-cdn.com/v4/letter/n/ebca7d/32.png) [@nisaxena](https://discuss.elastic.co/u/nisaxena)
#### Post date: [July 30, 2020, 9:56am UTC](https://discuss.elastic.co/t/need-help-in-listing-syslog-data-10000/242902/3 "2020-07-30T09:56:59Z")

</div>

Hi Mark,

My setup is big, there are 10000+ hosts reporting logs everyday and this number will keep on growing.

Need suggestion on how should I keep this data for easy listing / retrieval in visualisation.

A simple one for now, How can I visualise this data and get the **list** (not number) of all unique reported host on a day ?

So far I have created a single host, will a cluster pair help in this scenario ? Will it help in fast listing of data ?

Thanks,  
Nitin

---

<div class="post-metadata">

### Author: ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)
#### Post date: [July 30, 2020, 9:57am UTC](https://discuss.elastic.co/t/need-help-in-listing-syslog-data-10000/242902/4 "2020-07-30T09:57:50Z")

</div>

Why do you want to see over 10000 hosts in a table like that though? That is not really usable.

---

<div class="post-metadata">

### Author: ![nisaxena](https://avatars.discourse-cdn.com/v4/letter/n/ebca7d/32.png) [@nisaxena](https://discuss.elastic.co/u/nisaxena)
#### Post date: [July 30, 2020, 10:27am UTC](https://discuss.elastic.co/t/need-help-in-listing-syslog-data-10000/242902/5 "2020-07-30T10:27:11Z")

</div>

Hi Mark,

I am talking about visualization of data here at vertical / horizontal bar or any other visualization.

My Requirement, From the single Index logs-\* ( logs-YYYY-MM-DD ) I just wanted to see list of unique reported hosts.

Thanks,

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [August 27, 2020, 10:27am UTC](https://discuss.elastic.co/t/need-help-in-listing-syslog-data-10000/242902/6 "2020-08-27T10:27:16Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
