# Parsing Syslog to Logstash

**URL:** <https://discuss.elastic.co/t/parsing-syslog-to-logstash/218564>\
**Category:** Logstash\
**Created:** [February 10, 2020, 10:38am UTC](https://discuss.elastic.co/t/parsing-syslog-to-logstash/218564 "2020-02-10T10:38:40Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![marvine82](https://avatars.discourse-cdn.com/v4/letter/m/71c47a/32.png) [@marvine82](https://discuss.elastic.co/u/marvine82)\
**Post date:** [February 10, 2020, 10:38am UTC](https://discuss.elastic.co/t/parsing-syslog-to-logstash/218564/1 "2020-02-10T10:38:41Z")

</div>

Hey;

im currently trying to parse my syslog events to my elasticsearch host over logstash.  
I created a new .conf file under /etc/logstash/conf.d called syslog.conf.

This file looks like this:

* * *

input {  
syslog {  
port =\> 514  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

output {  
elasticsearch {  
hosts =\> "[http://b4d1syslog.b4dom1.local:9200](http://b4d1syslog.b4dom1.local:9200)"  
manage\_template =\> false  
index =\> "syslog"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

* * *

Sadly i cant get the logs to show up in Elasticsearch.  
When i type "tcpdump -A -i any dst port 514" I can see the right logs coming in, so my client is configured the right way.

I would be grateful if anyone could help me. Thx 🙂

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [February 10, 2020, 2:33pm UTC](https://discuss.elastic.co/t/parsing-syslog-to-logstash/218564/2 "2020-02-10T14:33:03Z")

</div>

Hi there,

when posting parts of code or response, please highlight your text and press this icon ![image](https://us1.discourse-cdn.com/elastic/original/3X/c/9/c9e97121fba1e8762c568c30c0bec76c3fb27175.png) to format it.

Anyway, can you paste here what is printed in `stdout` running the following pipeline?

```
input {
  syslog {
    port => 514
  }
}

filter {}

output {
  stdout{}
}
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [February 10, 2020, 3:22pm UTC](https://discuss.elastic.co/t/parsing-syslog-to-logstash/218564/3 "2020-02-10T15:22:35Z")

</div>

> [@marvine82](#):
>
> if [type] == "syslog" {

What makes you think that [type] will contain the value "syslog", and what makes you think [@metadata][type] will contain a value?

---

<div class="post-metadata">

**Author:** ![marvine82](https://avatars.discourse-cdn.com/v4/letter/m/71c47a/32.png) [@marvine82](https://discuss.elastic.co/u/marvine82)\
**Post date:** [February 11, 2020, 8:53am UTC](https://discuss.elastic.co/t/parsing-syslog-to-logstash/218564/4 "2020-02-11T08:53:23Z")

</div>

Hey,

to be honest i copied that part of the code... My goal is just to index all syslog data coming in at port 5541 to elasticsearch. Maybe you could give me a hint, how this can be accomplished?

Thanks in advance 🙂

---

<div class="post-metadata">

**Author:** ![Fabio-sama](https://avatars.discourse-cdn.com/v4/letter/f/b9e5f3/32.png) [@Fabio-sama](https://discuss.elastic.co/u/Fabio-sama)\
**Post date:** [February 11, 2020, 11:16am UTC](https://discuss.elastic.co/t/parsing-syslog-to-logstash/218564/5 "2020-02-11T11:16:48Z")

</div>

```
input {
  syslog {
    port => 5541
  }
}

filter {}

output {
  elasticsearch {
    hosts => "whatever_your_host_is:whatever_your_port_is"
    index => "whatever_your_index_is"
  }
}
```

---

<div class="post-metadata">

**Author:** ![marvine82](https://avatars.discourse-cdn.com/v4/letter/m/71c47a/32.png) [@marvine82](https://discuss.elastic.co/u/marvine82)\
**Post date:** [February 11, 2020, 12:17pm UTC](https://discuss.elastic.co/t/parsing-syslog-to-logstash/218564/6 "2020-02-11T12:17:31Z")

</div>

Thanks! 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 10, 2020, 12:17pm UTC](https://discuss.elastic.co/t/parsing-syslog-to-logstash/218564/7 "2020-03-10T12:17:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
