# Not able to recognize rsyslogs in SIEM

**URL:** <https://discuss.elastic.co/t/not-able-to-recognize-rsyslogs-in-siem/309750>\
**Category:** Logstash\
**Created:** [July 15, 2022, 3:30pm UTC](https://discuss.elastic.co/t/not-able-to-recognize-rsyslogs-in-siem/309750 "2022-07-15T15:30:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Rao\_Nelakurti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rao_nelakurti/32/98729_2.png) [@Rao\_Nelakurti](https://discuss.elastic.co/u/Rao_Nelakurti)\
**Post date:** [July 15, 2022, 3:30pm UTC](https://discuss.elastic.co/t/not-able-to-recognize-rsyslogs-in-siem/309750/1 "2022-07-15T15:30:40Z")

</div>

I'm trying to send rsyslogs to SIEM (rsyslog-\> filebeat-\> logstash-\> siem)  
filebeat.conf,

```auto
filebeat.spool_size: 2048
filebeat.idle_timeout: 5s
output.logstash:
  hosts: ['10.x.x.5:6045']
- type: log
  paths:
   - /var/log/hostname/forwarded-logs.log
  fields:
    logtype: rsyslog

```

Is there a file-beat plugin that supports rsyslog-output to SIEM? I didn't find anything?

I have looked at the alternative options to send logs to logstash, logstash to siem

logstash.conf:

```auto
input {
  beats {
    port => 6045
  }
}

filter{
  if [fields][logtype] == "rsyslog" {
       grok {
        match => ["message", "%{GREEDYDATA:message}"]
        add_tag => "rsyslog"
   }
  }
}

output {
  if "rsyslog" in [tags] {
       syslog {
        appname => "SIEM"
        host => "10.x.x.52"
        port => "514"
        protocol => "tcp"
        codec => line { format => "%{message}" }
    }
  }
  stdout{}
}

```

I'm not able recognize file-beat installed hostname in SIEM, What were my options in terms of recognizing file-beat installed hostname?

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [July 15, 2022, 3:55pm UTC](https://discuss.elastic.co/t/not-able-to-recognize-rsyslogs-in-siem/309750/2 "2022-07-15T15:55:24Z")

</div>

Can you share a sample of the message you are sending, what is the output you are getting and what is the desired output?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 16, 2022, 6:50am UTC](https://discuss.elastic.co/t/not-able-to-recognize-rsyslogs-in-siem/309750/3 "2022-07-16T06:50:14Z")

</div>

> [@Rao\_Nelakurti](#):
>
> `- type: log`

I am Not sure if that is supposed to be your entire, filebeat.yml

If it is, you're missing a pretty important line

```auto
filebeat.inputs
- type: log

```

---

<div class="post-metadata">

**Author:** ![Rao\_Nelakurti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rao_nelakurti/32/98729_2.png) [@Rao\_Nelakurti](https://discuss.elastic.co/u/Rao_Nelakurti)\
**Post date:** [July 18, 2022, 2:15pm UTC](https://discuss.elastic.co/t/not-able-to-recognize-rsyslogs-in-siem/309750/4 "2022-07-18T14:15:44Z")

</div>

@stephenb I did have that line in my filebeat.yml, can you confirm if we can send rsyslogs to external SIEM.

If yes, what was the plugin?

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [July 18, 2022, 2:33pm UTC](https://discuss.elastic.co/t/not-able-to-recognize-rsyslogs-in-siem/309750/5 "2022-07-18T14:33:19Z")

</div>

@Rao_Nelakurti

> [@Rao\_Nelakurti](#):
>
> can you confirm if we can send rsyslogs to external SIEM.
> 
> If yes, what was the plugin?

I am not sure what you are asking, it would help if you could be a little more detailed in your questions.

Are you asking  
_Can you send logs that are harvested with filebeat and sent through logstash can they be forwarded to a syslog output with logstash?_

If that is the question then the answer is yes.

If you are asking  
_Can logs be harvested somehow and sent to a random external SIEM that has not been identified_

I have no clue because there is not enough information.

If your real question is

_What were my options in terms of recognizing file-beat installed hostname?_

You would need to do some parsing of the logs and set the correct fields.

And if that is the case what @leandrojmp asked is very important you need to show the indata and out data so we could help.

> [@leandrojmp](#):
>
> Can you share a sample of the message you are sending, what is the output you are getting and what is the desired output?

---

<div class="post-metadata">

**Author:** ![Rao\_Nelakurti](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rao_nelakurti/32/98729_2.png) [@Rao\_Nelakurti](https://discuss.elastic.co/u/Rao_Nelakurti)\
**Post date:** [July 18, 2022, 2:59pm UTC](https://discuss.elastic.co/t/not-able-to-recognize-rsyslogs-in-siem/309750/6 "2022-07-18T14:59:08Z")

</div>

@stephenb @leandrojmp

What I'm trying here send rsyslogs to Security Information and Event Management (McaFee SIEM)

What were my options in terms of recognizing file-beat installed hostname in SIEM?

Here is my input rsyslog forwarded-logs.log:

```auto
2022-07-18T14:16:01.363926+00:00 scmgxpbt-wls-1 CROND[27856]: (root) CMD (python < /usr/share/rhn/virtualization/poller.py)
2022-07-18T14:16:45.663113+00:00 scmgxpbt-wls-1 runuser: pam_unix(runuser:session): session opened for user root by opc(uid=0)

```

I'm collecting above log through filebeat and sending it to logstash output.  
Logstash will send it to SIEM.

Here is my Logstash output,

```auto
       "message" => [
        [0] "2022-07-18T14:58:01.495362+00:00 scmgxpbt-wls-1 CROND[25968]: (root) CMD (python < /usr/share/rhn/virtualization/poller.py)",
        [1] "2022-07-18T14:58:01.495362+00:00 scmgxpbt-wls-1 CROND[25968]: (root) CMD (python < /usr/share/rhn/virtualization/poller.py)"
    ],
          "host" => {
        "name" => "scmgxpbt-wls-1"
    },
    "@timestamp" => 2022-07-18T14:58:01.998Z,
         "agent" => {
            "hostname" => "scmgxpbt-wls-1",
                  "id" => "b92b643f-a1a5-4f44-ab1f-693a53df9ef2",
                "type" => "filebeat",
             "version" => "7.3.1",
        "ephemeral_id" => "20f7a094-15ed-4e97-87bf-402b018db944"
    },
         "input" => {
        "type" => "log"
    },
      "@version" => "1",
        "fields" => {
        "envName" => "gxpbt",
        "logtype" => "rsyslog"
    },
          "tags" => [
        [0] "beats_input_codec_plain_applied",
        [1] "rsyslog"
    ],
           "log" => {
          "file" => {
            "path" => "/var/log/scmgxpbt-wls-1/forwarded-logs.log"
        },
        "offset" => 2107278
    }

```

I have added filebeat.conf file and logstash.conf file in my first post.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 15, 2022, 2:59pm UTC](https://discuss.elastic.co/t/not-able-to-recognize-rsyslogs-in-siem/309750/7 "2022-08-15T14:59:32Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
