# Send full syslog unparsed message

**URL:** https://discuss.elastic.co/t/send-full-syslog-unparsed-message/195468
**Category:** Beats
**Tags:** filebeat
**Created:** [August 16, 2019, 9:57am UTC](https://discuss.elastic.co/t/send-full-syslog-unparsed-message/195468 "2019-08-16T09:57:32Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![probson](https://avatars.discourse-cdn.com/v4/letter/p/e47c2d/32.png) [@probson](https://discuss.elastic.co/u/probson)
#### Post date: [August 16, 2019, 9:57am UTC](https://discuss.elastic.co/t/send-full-syslog-unparsed-message/195468/1 "2019-08-16T09:57:32Z")

</div>

Hi,

I am using filebeat to collect syslogs from a cisco firepower IPS straight to logstash. Filebeat is able to parse the time, the issue is that firepower sends the time in RFC3164 in UTC. Filebeat is parsing the syslog timestamp but removing another hour, as such my logs are an hour behind UTC.

Is it possible to access the original unparsed message in logstash so that i can get the SYSLOGTIMESTAMP?

I have been trying to use the below in logstash to no avail.

date {  
match =\> ["timestamp", "MMM dd HH:mm:ss", "ISO8601"]  
timezone =\> "UTC"  
}

Looking at the pipelines in filebeat for elasticsearch it looks as though it expects the full syslog message.

Any pointers?

Thanks  
Phil

---

<div class="post-metadata">

### Author: ![steffens](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/steffens/32/79630_2.png) [@steffens](https://discuss.elastic.co/u/steffens)
#### Post date: [August 16, 2019, 12:08pm UTC](https://discuss.elastic.co/t/send-full-syslog-unparsed-message/195468/2 "2019-08-16T12:08:00Z")

</div>

If you want to do all parsing and processing, then you might want to use the tcp and/or udp inputs directly. Internally the syslog input just reuses those two inputs, but adds parsing on top.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [September 13, 2019, 12:10pm UTC](https://discuss.elastic.co/t/send-full-syslog-unparsed-message/195468/3 "2019-09-13T12:10:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
