# New to ELK (Syslog issue)

**URL:** <https://discuss.elastic.co/t/new-to-elk-syslog-issue/54141>\
**Category:** Logstash\
**Created:** [June 28, 2016, 10:02am UTC](https://discuss.elastic.co/t/new-to-elk-syslog-issue/54141 "2016-06-28T10:02:26Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Tommo](https://avatars.discourse-cdn.com/v4/letter/t/ebca7d/32.png) [@Tommo](https://discuss.elastic.co/u/Tommo)\
**Post date:** [June 28, 2016, 10:02am UTC](https://discuss.elastic.co/t/new-to-elk-syslog-issue/54141/1 "2016-06-28T10:02:26Z")

</div>

I've setup ELK on Windows 2012 and can't seem to get the syslog working.  
So at this stage my logstash.json file has a simple input for syslog.

input {  
beats {  
port =\> 5044  
type =\> log  
}  
syslog {  
}  
If I save this and restart the logstash service I would expect netstat -a | find "514" to return a listener but it's not.  
The filebeats, winlogbeats and topbeat are functioning as expected.

If I do a logstash-plugin list --verbose I can see that logstash-input-syslog is version (2.0.5).

So my question is does someone have a simple setup documented I can review for syslog on windows.

cheers  
Tom

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [June 29, 2016, 2:57pm UTC](https://discuss.elastic.co/t/new-to-elk-syslog-issue/54141/2 "2016-06-29T14:57:35Z")

</div>

Have you tried specifically bonding a given host IP and/or port?

If you run with the `--verbose` or `--debug` flags, do you see more information regarding the syslog input plugin?

---

<div class="post-metadata">

**Author:** ![Tommo](https://avatars.discourse-cdn.com/v4/letter/t/ebca7d/32.png) [@Tommo](https://discuss.elastic.co/u/Tommo)\
**Post date:** [July 1, 2016, 6:42am UTC](https://discuss.elastic.co/t/new-to-elk-syslog-issue/54141/3 "2016-07-01T06:42:23Z")

</div>

Thanks for the reply I ended up dumping the windows box and running ELK on cents as I found more tuts I could follow.  
I will return to windows once I have it all doing what I hope.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:49am UTC](https://discuss.elastic.co/t/new-to-elk-syslog-issue/54141/4 "2017-07-06T04:49:57Z")

</div>


