# Parse "message" field on Syslog

**URL:** <https://discuss.elastic.co/t/parse-message-field-on-syslog/265729>\
**Category:** Logstash\
**Created:** [February 28, 2021, 3:17pm UTC](https://discuss.elastic.co/t/parse-message-field-on-syslog/265729 "2021-02-28T15:17:53Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Santiago\_Fernandez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/santiago_fernandez/32/84672_2.png) [@Santiago\_Fernandez](https://discuss.elastic.co/u/Santiago_Fernandez)\
**Post date:** [February 28, 2021, 3:17pm UTC](https://discuss.elastic.co/t/parse-message-field-on-syslog/265729/1 "2021-02-28T15:17:53Z")

</div>

Hi Guys! I m new in ELK.

have managed to get the Stack up and send my syslogs from my API Manager.

I would like to be able to transform a Syslog field into JSON. The "message" field.

This is my logstash.conf

> input {  
> tcp {  
> port =\> 5000  
> type =\> syslog  
> }  
> udp {  
> port =\> 5000  
> type =\> syslog  
> }  
> }
> 
> filter {  
> if [type] == "syslog" {  
> grok {  
> match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
> add\_field =\> ["received\_at", "%{@timestamp}"]  
> add\_field =\> ["received\_from", "%{host}"]  
> }  
> date {  
> match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
> }  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> "elasticsearch:9200"  
> user =\> elastic  
> password =\> yourstrongpasswordhere  
> }  
> stdout { codec =\> rubydebug }  
> }

Hire mi log on ELK.

 ![Log](https://us1.discourse-cdn.com/elastic/original/3X/7/c/7c4d29e7e3e4ff0de29562069d16051bd9e6c428.png)

I understand that I am not the first to inquire about this issue. Where can I start reading, to solve it?

Thanks a lot.

---

<div class="post-metadata">

**Author:** ![stephenb](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stephenb/32/40856_2.png) [@stephenb](https://discuss.elastic.co/u/stephenb)\
**Post date:** [February 28, 2021, 4:53pm UTC](https://discuss.elastic.co/t/parse-message-field-on-syslog/265729/2 "2021-02-28T16:53:49Z")

</div>

Hi @Santiago_Fernandez Welcome to the community!

First it is really hard to help when you post screen shots instead if text it's harder to help and can't be tested / searched etc.

That said .. hard to tell but that looks like a json field so perhaps take a look at [this](https://www.elastic.co/guide/en/logstash/current/plugins-filters-json.html)

---

<div class="post-metadata">

**Author:** ![Santiago\_Fernandez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/santiago_fernandez/32/84672_2.png) [@Santiago\_Fernandez](https://discuss.elastic.co/u/Santiago_Fernandez)\
**Post date:** [February 28, 2021, 6:01pm UTC](https://discuss.elastic.co/t/parse-message-field-on-syslog/265729/3 "2021-02-28T18:01:20Z")

</div>

Hi @stephenb, thanks for your reply!

Here you are.

> @timestamp  
> Feb 28, 2021 @ 13:00:09.681
> 
> @version  
> 1
> 
> \_id  
> K0Ze6XcBV6EJI8QRVqc8
> 
> \_index  
> logstash-2021.02.28-000001
> 
> ## \_score
> 
> \_type  
> \_doc
> 
> host  
> gateway
> 
> message  
> {"latencies":{"request":7,"kong":0,"proxy":7},"service":{"host":"api","created\_at":1614459071,"connect\_timeout":60000,"id":"da7fd962-317e-4757-a347-3f0da3886e6c","protocol":"http","name":"MyAPI","read\_timeout":60000,"port":5000,"updated\_at":1614459071,"ws\_id":"6e2ab00c-1e33-448c-a1ca-180f5a0f57ba","retries":5,"write\_timeout":60000},"request":{"querystring":{},"size":153,"uri":"/frase/29","url":"[http://api.local:8000/frase/29","headers":{"host":"api.local:8000","accept-encoding":"gzip](http://api.local:8000/frase/29%22,%22headers%22:%7B%22host%22:%22api.local:8000%22,%22accept-encoding%22:%22gzip), deflate","user-agent":"python-requests/2.25.1","accept":"_/_","connection":"keep-alive"},"method":"GET"},"client\_ip":"192.168.0.209","tries":[{"balancer\_latency":0,"port":5000,"balancer\_start":1614528009794,"ip":"172.27.0.7"}],"upstream\_uri":"/frase/29","response":{"headers":{"via":"kong/2.3.2","content-type":"application/json","date":"Sun, 28 Feb 2021 16:00:09 GMT","server":"Werkzeug/1.0.1 Python/3.6.13","connection":"close","x-kong-proxy-latency":"0","x-kong-upstream-latency":"7","content-length":"248"},"status":200,"size":489},"route":{"created\_at":1614459089,"ws\_id":"6e2ab00c-1e33-448c-a1ca-180f5a0f57ba","id":"e6d9b7ae-a9f2-40c0-b1bf-a7f1aa14f3d9","path\_handling":"v0","name":"main","request\_buffering":true,"service":{"id":"da7fd962-317e-4757-a347-3f0da3886e6c"},"preserve\_host":false,"regex\_priority":0,"response\_buffering":true,"updated\_at":1614459089,"paths":["/"],"https\_redirect\_status\_code":426,"protocols":["http","https"],"strip\_path":true},"started\_at":1614528009794}
> 
> port  
> 59366
> 
> tags  
> \_grokparsefailure
> 
> type  
> syslog

An going to read the link!

---

<div class="post-metadata">

**Author:** ![Santiago\_Fernandez](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/santiago_fernandez/32/84672_2.png) [@Santiago\_Fernandez](https://discuss.elastic.co/u/Santiago_Fernandez)\
**Post date:** [February 28, 2021, 6:53pm UTC](https://discuss.elastic.co/t/parse-message-field-on-syslog/265729/4 "2021-02-28T18:53:17Z")

</div>

Hi i resolve with this!

> input {  
> tcp {  
> port =\> 5000  
> type =\> syslog  
> }  
> udp {  
> port =\> 5000  
> type =\> syslog  
> }  
> }
> 
> filter {  
> if [type] == "syslog" {  
> grok {  
> match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
> add\_field =\> ["received\_at", "%{@timestamp}"]  
> add\_field =\> ["received\_from", "%{host}"]  
> }  
> json {  
> source =\> "message"  
> }  
> date {  
> match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
> }  
> }  
> }
> 
> output {  
> elasticsearch {  
> hosts =\> "elasticsearch:9200"  
> user =\> elastic  
> password =\> yourstrongpasswordhere  
> }  
> stdout { codec =\> rubydebug }  
> }

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 28, 2021, 6:53pm UTC](https://discuss.elastic.co/t/parse-message-field-on-syslog/265729/5 "2021-03-28T18:53:47Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
