# Parsing syslog data: Need help understanding documentation example

**URL:** <https://discuss.elastic.co/t/parsing-syslog-data-need-help-understanding-documentation-example/37416>\
**Category:** Logstash\
**Created:** [December 16, 2015, 11:26pm UTC](https://discuss.elastic.co/t/parsing-syslog-data-need-help-understanding-documentation-example/37416 "2015-12-16T23:26:09Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![gaurav1424](https://avatars.discourse-cdn.com/v4/letter/g/97f17d/32.png) [@gaurav1424](https://discuss.elastic.co/u/gaurav1424)\
**Post date:** [December 16, 2015, 11:26pm UTC](https://discuss.elastic.co/t/parsing-syslog-data-need-help-understanding-documentation-example/37416/1 "2015-12-16T23:26:09Z")

</div>

Hello All,

I am referring logstash example of parsing syslog data : [https://www.elastic.co/guide/en/logstash/current/config-examples.html#\_processing\_syslog\_messages](https://www.elastic.co/guide/en/logstash/current/config-examples.html#_processing_syslog_messages)

My input line is :  
Dec 3 01:22:48 arista1.lab ProcMgr-worker: %PROCMGR-7-NEW\_PROCESSES: New processes configured to run under ProcMgr control: ['PciBus', 'Picasso', 'PlxPcie', 'PlxPcie-system']

What I have output with same config mentioned in above link :

{  
"message" =\> "Dec 3 01:22:48 arista1.lab ProcMgr-worker: %PROCMGR-7-NEW\_PROCESSES: New processes configured to run under ProcMgr control: ['PciBus', 'Picasso', 'PlxPcie', 'PlxPcie-system']\r",  
"@version" =\> "1",  
"@timestamp" =\> "2015-12-03T09:22:48.000Z",  
"host" =\> "0:0:0:0:0:0:0:1",  
"type" =\> "syslog",  
"syslog\_timestamp" =\> "Dec 3 01:22:48",  
"syslog\_hostname" =\> "arista1.lab",  
"syslog\_program" =\> "ProcMgr-worker",  
"syslog\_message" =\> "%PROCMGR-7-NEW\_PROCESSES: New processes configured to run under ProcMgr control: ['PciBus', 'Picasso', 'PlxPcie', 'PlxPcie-system']\r",  
"received\_at" =\> "2015-12-15T15:46:37.596Z",  
"received\_from" =\> "0:0:0:0:0:0:0:1",  
"syslog\_severity\_code" =\> 5,  
"syslog\_facility\_code" =\> 1,  
"syslog\_facility" =\> "user-level",  
"syslog\_severity" =\> "notice"  
}

Questions :  
1: How did it get "@version" =\> "1" ?  
2: Why @timestamp and received\_at are different timestamps, I should get almost same time at which this event was sent, right ?  
3: I know this is coming from syslog\_pri {}  
How did it get these fields, My input line does not seem to have these values anywhere.  
"syslog\_severity\_code" =\> 5,  
"syslog\_facility\_code" =\> 1,  
"syslog\_facility" =\> "user-level",  
"syslog\_severity" =\> "notice"

Thanks !

---

<div class="post-metadata">

**Author:** ![gaurav1424](https://avatars.discourse-cdn.com/v4/letter/g/97f17d/32.png) [@gaurav1424](https://discuss.elastic.co/u/gaurav1424)\
**Post date:** [December 16, 2015, 11:28pm UTC](https://discuss.elastic.co/t/parsing-syslog-data-need-help-understanding-documentation-example/37416/2 "2015-12-16T23:28:21Z")

</div>

Also why I am seeing "message" =\> as first line of parsed data. I dont want to see my message again.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [December 17, 2015, 10:44am UTC](https://discuss.elastic.co/t/parsing-syslog-data-need-help-understanding-documentation-example/37416/3 "2015-12-17T10:44:10Z")

</div>

1. It's always added to indicate the schema of the message. Previously the `message` field was named `@message` and I think `@version` was added around that time so that consumers of the messages would know what to expect.
2. Yes, but you're obviously parsing a message from Dec 3 and the `@timestamp` field should reflect the time an event occurred.
3. It's the [syslog\_pri filter](https://www.elastic.co/guide/en/logstash/current/plugins-filters-syslog_pri.html) that's does this.

> Also why I am seeing "message" =\> as first line of parsed data. I dont want to see my message again.

Then delete or overwrite that field. I prefer overwriting it with the actual message payload.

```auto
grok {
  match => ["message", "... %{GREEDYDATA:message}"]
  overwrite => ["message"]
}

```

---

<div class="post-metadata">

**Author:** ![gaurav1424](https://avatars.discourse-cdn.com/v4/letter/g/97f17d/32.png) [@gaurav1424](https://discuss.elastic.co/u/gaurav1424)\
**Post date:** [December 17, 2015, 7:27pm UTC](https://discuss.elastic.co/t/parsing-syslog-data-need-help-understanding-documentation-example/37416/4 "2015-12-17T19:27:43Z")

</div>

> [@gaurav1424](#):
>
> "host" =\> "0:0:0:0:0:0:0:1", "type" =\> "syslog",

Thanks a lot once again !

May I know how can I prevent certain Key: value pairs getting displayed in my logstash output section ?  
for eg :  
I dont want these lines in my output :

"host" =\> "0:0:0:0:0:0:0:1",  
"type" =\> "syslog",

---

<div class="post-metadata">

**Author:** ![gaurav1424](https://avatars.discourse-cdn.com/v4/letter/g/97f17d/32.png) [@gaurav1424](https://discuss.elastic.co/u/gaurav1424)\
**Post date:** [December 17, 2015, 8:01pm UTC](https://discuss.elastic.co/t/parsing-syslog-data-need-help-understanding-documentation-example/37416/5 "2015-12-17T20:01:58Z")

</div>

I figured out with remove\_field option.

Thanks !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:17am UTC](https://discuss.elastic.co/t/parsing-syslog-data-need-help-understanding-documentation-example/37416/6 "2017-07-06T05:17:58Z")

</div>


