# Receiving remote logs in logstash

**URL:** <https://discuss.elastic.co/t/receiving-remote-logs-in-logstash/240234>\
**Category:** Logstash\
**Created:** [July 7, 2020, 11:22pm UTC](https://discuss.elastic.co/t/receiving-remote-logs-in-logstash/240234 "2020-07-07T23:22:25Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![orlapa](https://avatars.discourse-cdn.com/v4/letter/o/77aa72/32.png) [@orlapa](https://discuss.elastic.co/u/orlapa)\
**Post date:** [July 7, 2020, 11:22pm UTC](https://discuss.elastic.co/t/receiving-remote-logs-in-logstash/240234/1 "2020-07-07T23:22:25Z")

</div>

I have configured a HSM to send lodgs via TCP to logstash listening in pot 5004, but nothing arrive. I did a test with Rsyslog in port 514 and the logs arrive. Where should I focus the serach for error, the services are up (Elastic, logstash and KIbana).  
THanks for the help  
ELK is installed on Centos 7

---

<div class="post-metadata">

**Author:** ![warkolm](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/warkolm/32/39224_2.png) [@warkolm](https://discuss.elastic.co/u/warkolm)\
**Post date:** [July 7, 2020, 11:29pm UTC](https://discuss.elastic.co/t/receiving-remote-logs-in-logstash/240234/2 "2020-07-07T23:29:37Z")

</div>

What is HSM?  
What does your config for Logstash look like? What version are you running?

---

<div class="post-metadata">

**Author:** ![orlapa](https://avatars.discourse-cdn.com/v4/letter/o/77aa72/32.png) [@orlapa](https://discuss.elastic.co/u/orlapa)\
**Post date:** [July 8, 2020, 1:28pm UTC](https://discuss.elastic.co/t/receiving-remote-logs-in-logstash/240234/3 "2020-07-08T13:28:23Z")

</div>

Hi,  
Thanks for your response, HSM is an Harware Security Module or criptographic server, it can send the logs by TCP or UPD in format SYSLOG or CEF, I am sending by TCP SYSLOG.  
Installed Packages  
logstash.noarch 1:7.1.1-1 @elasticsearch-7.x

Config files  
[root@localhost ~]# cat /etc/logstash/conf.d/\*  
input {  
tcp {  
# beats  
port =\> 5004  
type =\> "syslog"  
}  
}

```
filter {
	if [type] == "syslog" {
    	grok {
          	match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
          	add_field => ["received_at", "%{@timestamp}"]
          	add_field => ["received_from", "%{host}"]
        }
        syslog_pri { }
        date {
          	match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
        }
	}
    }

output {
  	elasticsearch {
    	hosts => ["http://52.xxx.xxx.212:9200"]
    	index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
  	}
}

```

ip masked by security reasons  
I am new on ELK, so all advises are welcome  
Regards

---

<div class="post-metadata">

**Author:** ![fadjar340](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fadjar340/32/43610_2.png) [@fadjar340](https://discuss.elastic.co/u/fadjar340)\
**Post date:** [July 8, 2020, 4:14pm UTC](https://discuss.elastic.co/t/receiving-remote-logs-in-logstash/240234/4 "2020-07-08T16:14:39Z")

</div>

What is your HSM log delivery config? Is it to port 5004 or 514?

---

<div class="post-metadata">

**Author:** ![orlapa](https://avatars.discourse-cdn.com/v4/letter/o/77aa72/32.png) [@orlapa](https://discuss.elastic.co/u/orlapa)\
**Post date:** [July 9, 2020, 5:36pm UTC](https://discuss.elastic.co/t/receiving-remote-logs-in-logstash/240234/5 "2020-07-09T17:36:23Z")

</div>

I have done a clean install and now I am verified that the logs are arriving...

 ![evidence1](https://us1.discourse-cdn.com/elastic/original/3X/0/3/03ff34f2bbe968b248833c3ea52de674a32b31a9.png)  
But I can not see the logs on kibana...  
Any ideas?,  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 6, 2020, 5:36pm UTC](https://discuss.elastic.co/t/receiving-remote-logs-in-logstash/240234/6 "2020-08-06T17:36:30Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
