# Regexp in conditional

**URL:** <https://discuss.elastic.co/t/regexp-in-conditional/194223>\
**Category:** Logstash\
**Created:** [August 7, 2019, 11:31am UTC](https://discuss.elastic.co/t/regexp-in-conditional/194223 "2019-08-07T11:31:42Z")\
**Posts on this page:** 1\
**Showing post:** 10

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [August 9, 2019, 12:59pm UTC](https://discuss.elastic.co/t/regexp-in-conditional/194223/10 "2019-08-09T12:59:22Z")

</div>

You are using syslog output and input to move events between logstash instances? I would suggest switching to a lumberjack output and a beats input. If you are really married to syslog you can do something like [this](https://discuss.elastic.co/t/logstash-output-syslog-full-json-in-message/142642/6) to send the entire event.

---

_[View the full topic](https://discuss.elastic.co/t/regexp-in-conditional/194223)._
