# Parsing syslog from linux rsyslog

**URL:** <https://discuss.elastic.co/t/parsing-syslog-from-linux-rsyslog/31267>\
**Category:** Logstash\
**Created:** [September 28, 2015, 3:16pm UTC](https://discuss.elastic.co/t/parsing-syslog-from-linux-rsyslog/31267 "2015-09-28T15:16:46Z")\
**Posts on this page:** 6\
**Page:** 2

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 30, 2015, 1:51pm UTC](https://discuss.elastic.co/t/parsing-syslog-from-linux-rsyslog/31267/21 "2015-09-30T13:51:45Z")

</div>

> Yes, the messages are reaching Logstash.

How do you know?

> You mean that changing like this?
> 
> output{  
> stdout { codec =\> rubydebug }  
> }

Yes. Now, are the incoming messages written to Logstash's stdout, probably connected to /var/log/logstash/logstash.stdout or similar if you're starting Logstash as a service?

> after that trying again to kibana?

No. Forget about Kibana for now.

---

<div class="post-metadata">

**Author:** ![cnozmn](https://avatars.discourse-cdn.com/v4/letter/c/9de053/32.png) [@cnozmn](https://discuss.elastic.co/u/cnozmn)\
**Post date:** [September 30, 2015, 2:03pm UTC](https://discuss.elastic.co/t/parsing-syslog-from-linux-rsyslog/31267/22 "2015-09-30T14:03:49Z")

</div>

when enable the elasticsearch output "/var/log/logstash/logstash.stdout"

```
{
                 "message" => "\r",
                "@version" => "1",
              "@timestamp" => "2015-09-30T13:40:57.498Z",
                    "host" => "0:0:0:0:0:0:0:1",
                    "type" => "syslog",
                    "tags" => [
        [0] "_grokparsefailure"
    ],
    "syslog_severity_code" => 5,
    "syslog_facility_code" => 1,
         "syslog_facility" => "user-level",
         "syslog_severity" => "notice"

```

when disable the elasticsearch output, there is only this message "sending logstash logs to /var/log/logstash/logstash.log"

so I looked that file "logstash.log", there are many syslogs with started {:timestamp=\>"2015... etc.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 30, 2015, 2:15pm UTC](https://discuss.elastic.co/t/parsing-syslog-from-linux-rsyslog/31267/23 "2015-09-30T14:15:49Z")

</div>

Did you mix up "enable" and "disable"? Surely you're getting the output above when _disabling_ the elasticsearch output?

Anyway, this certainly proves that Logstash is getting the messages. But what's the lone carriage return character ("\r") doing there? Is that what's being sent over the wire? It looks like garbage.

---

<div class="post-metadata">

**Author:** ![otisg](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/otisg/32/492_2.png) [@otisg](https://discuss.elastic.co/u/otisg)\
**Post date:** [September 30, 2015, 2:30pm UTC](https://discuss.elastic.co/t/parsing-syslog-from-linux-rsyslog/31267/25 "2015-09-30T14:30:36Z")

</div>

Hi,

We have a LOT of syslog/rsyslog/Logstash resources over on [http://blog.sematext.com](http://blog.sematext.com) . e.g. here's a related one from 2 days ago: [http://blog.sematext.com/2015/09/28/recipe-rsyslog-redis-logstash/](http://blog.sematext.com/2015/09/28/recipe-rsyslog-redis-logstash/) . I think this URL will show you various rsyslog + Logstash posts, many of which are howto style posts: [http://blog.sematext.com/tag/syslog,logstash/](http://blog.sematext.com/tag/syslog,logstash/)

HTH!

Otis

---

<div class="post-metadata">

**Author:** ![cnozmn](https://avatars.discourse-cdn.com/v4/letter/c/9de053/32.png) [@cnozmn](https://discuss.elastic.co/u/cnozmn)\
**Post date:** [September 30, 2015, 3:16pm UTC](https://discuss.elastic.co/t/parsing-syslog-from-linux-rsyslog/31267/26 "2015-09-30T15:16:54Z")

</div>

When I tried "telnet localhost 514" with coming syslog ( I have seen it with "tcpdump" and copied-pasted with telnet),  
in the logstash.stdout, there is a significant log. So its parsing if I send with telnet..

so what should I do? Do you have an idea ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:27am UTC](https://discuss.elastic.co/t/parsing-syslog-from-linux-rsyslog/31267/27 "2017-07-06T05:27:38Z")

</div>



[Previous page](https://discuss.elastic.co/t/parsing-syslog-from-linux-rsyslog/31267.md?page=1)
