# Parse syslog-ng log to elasticsearch

**URL:** <https://discuss.elastic.co/t/parse-syslog-ng-log-to-elasticsearch/197830>\
**Category:** Logs\
**Created:** [September 3, 2019, 11:12am UTC](https://discuss.elastic.co/t/parse-syslog-ng-log-to-elasticsearch/197830 "2019-09-03T11:12:08Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ravipemmasani](https://avatars.discourse-cdn.com/v4/letter/r/ccd318/32.png) [@ravipemmasani](https://discuss.elastic.co/u/ravipemmasani)\
**Post date:** [September 3, 2019, 11:12am UTC](https://discuss.elastic.co/t/parse-syslog-ng-log-to-elasticsearch/197830/1 "2019-09-03T11:12:08Z")

</div>

Hi All,  
Iam glad to join this group.  
Basically i'm in the midst of setting up POC for centralize log collection and analyse the log.  
Following is my setup on RHEL 7.6.  
Syslog-ng-collect log from remote clients  
Elasticsearch  
Kibana  
Need your help to provide sample config file to parse syslog-ng log to elasticsearch and create index pattern,really appreciate your help.

Thanks

---

<div class="post-metadata">

**Author:** ![fekete\_robert](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fekete_robert/32/23144_2.png) [@fekete\_robert](https://discuss.elastic.co/u/fekete_robert)\
**Post date:** [September 4, 2019, 6:27am UTC](https://discuss.elastic.co/t/parse-syslog-ng-log-to-elasticsearch/197830/2 "2019-09-04T06:27:35Z")

</div>

Hi,

The syslog-ng blog has regular posts about using syslog-ng with elastic. This post is about [setting up Elastic 7 and receive logs from syslog-ng](https://www.syslog-ng.com/community/b/blog/posts/syslog-ng-with-elastic-stack-7).

---

<div class="post-metadata">

**Author:** ![weltenwort](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/weltenwort/32/53885_2.png) [@weltenwort](https://discuss.elastic.co/u/weltenwort)\
**Post date:** [September 4, 2019, 8:48am UTC](https://discuss.elastic.co/t/parse-syslog-ng-log-to-elasticsearch/197830/3 "2019-09-04T08:48:52Z")

</div>

Hi @ravipemmasani,

the [`system` module](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-system.html) included in filebeat also consumes the syslog.

If running a lightweight shipper like filebeat on the edge system is not an option, there is also the [`syslog` input](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-syslog.html) in filebeat, which can receive remote syslog events via UDP or TCP.

The advantage with both of these would be that filebeat manages most of the index mapping for you if you let it ship the data directly to Elasticsearch.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 2, 2019, 8:49am UTC](https://discuss.elastic.co/t/parse-syslog-ng-log-to-elasticsearch/197830/4 "2019-10-02T08:49:00Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
