# Rsyslog and ELK

**URL:** <https://discuss.elastic.co/t/rsyslog-and-elk/548>\
**Category:** Logstash\
**Created:** [May 12, 2015, 11:54am UTC](https://discuss.elastic.co/t/rsyslog-and-elk/548 "2015-05-12T11:54:12Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![Sdclmb](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@Sdclmb](https://discuss.elastic.co/u/Sdclmb)\
**Post date:** [May 12, 2015, 11:54am UTC](https://discuss.elastic.co/t/rsyslog-and-elk/548/1 "2015-05-12T11:54:12Z")

</div>

hello,

I was aked to install a Log server with rsyslog or syslog-ng(don't know which one is better) and to analysis this data with ELK. My question is : is it possible to tell stack ELK to get the log on the first server ?

---

<div class="post-metadata">

**Author:** ![JeremyinNC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremyinnc/32/44868_2.png) [@JeremyinNC](https://discuss.elastic.co/u/JeremyinNC)\
**Post date:** [May 12, 2015, 12:15pm UTC](https://discuss.elastic.co/t/rsyslog-and-elk/548/2 "2015-05-12T12:15:00Z")

</div>

When you say "the first server" do you mean on the rsyslog log server? Or on the client machine sending to the rsyslog server? You can do either, as well as using logstash as the receiver from a client running rsyslog.

IMO syslog-ng is not worth using unless you have BSD based clients (Mac, Free/OpenBSD etc).

---

<div class="post-metadata">

**Author:** ![Sdclmb](https://avatars.discourse-cdn.com/v4/letter/s/e95f7d/32.png) [@Sdclmb](https://discuss.elastic.co/u/Sdclmb)\
**Post date:** [May 12, 2015, 12:26pm UTC](https://discuss.elastic.co/t/rsyslog-and-elk/548/3 "2015-05-12T12:26:54Z")

</div>

yes i meant the syslog server, so when i install logstash on an ohter server, i have to tell logstash to get the log from the syslog server then ?

And thanks for helping me 😄

---

<div class="post-metadata">

**Author:** ![JeremyinNC](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/jeremyinnc/32/44868_2.png) [@JeremyinNC](https://discuss.elastic.co/u/JeremyinNC)\
**Post date:** [May 12, 2015, 4:42pm UTC](https://discuss.elastic.co/t/rsyslog-and-elk/548/4 "2015-05-12T16:42:37Z")

</div>

You can just install logstash itself - it can receive syslog formatted messages from syslog compadible clients.

So on your clients' config /etc/rsyslog.d/60-logstash.conf

> _._;auth.authpriv.none @@logstash.example.com

will send everything but auth logs via TCP to your logstash server. On the logstash server use the [syslog input filter](http://logstash.net/docs/1.4.2/inputs/syslog)

Another option is to install the [file input](http://logstash.net/docs/1.4.2/inputs/file) on the syslog **server** and have it look at /var/log/stuff

---

<div class="post-metadata">

**Author:** ![theuntergeek](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/theuntergeek/32/44961_2.png) [@theuntergeek](https://discuss.elastic.co/u/theuntergeek)\
**Post date:** [May 12, 2015, 6:47pm UTC](https://discuss.elastic.co/t/rsyslog-and-elk/548/5 "2015-05-12T18:47:51Z")

</div>

If you're using a recent version of Rsyslog, you can bypass the need for regular-expression/grok extraction of the raw syslog data with something like this: [https://gist.github.com/untergeek/0373ee85a41d03ae1b78](https://gist.github.com/untergeek/0373ee85a41d03ae1b78)

The json output module for Rsyslog is awesome that way. 😄

---

<div class="post-metadata">

**Author:** ![elisiano](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/elisiano/32/44864_2.png) [@elisiano](https://discuss.elastic.co/u/elisiano)\
**Post date:** [May 12, 2015, 7:39pm UTC](https://discuss.elastic.co/t/rsyslog-and-elk/548/6 "2015-05-12T19:39:22Z")

</div>

Starting with a new technology in most cases means doing iterations until you reached the goal you want.  
When starting with the ELK stack, I found it easier (and more 'boss'-compliant 😄) to have a central (r)syslog server collecting data from all other servers/client in a certain directory ( i.e.: `/data/log/<HOSTNAME>/<YEAR>/<MONTH>/<DAY>/<FACILITY>.log`) and then having logstash on the same server reading file inputs and outputting to elasticsearch (which could be on a different server).

Having this architecture you basically decouple logging (done with rsyslog) from ELK.  
It was useful especially when learning how to 'grok' events to do some manipulation (if I messed up, I could delete the elastic search indices and start over).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:39am UTC](https://discuss.elastic.co/t/rsyslog-and-elk/548/7 "2017-07-06T05:39:57Z")

</div>


