# Send Linux/Windows/NetworkDevices logs to Elastic SIEM

**URL:** <https://discuss.elastic.co/t/send-linux-windows-networkdevices-logs-to-elastic-siem/238903>\
**Category:** SIEM\
**Created:** [June 26, 2020, 6:40pm UTC](https://discuss.elastic.co/t/send-linux-windows-networkdevices-logs-to-elastic-siem/238903 "2020-06-26T18:40:09Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![jelocabral](https://avatars.discourse-cdn.com/v4/letter/j/e0b2c6/32.png) [@jelocabral](https://discuss.elastic.co/u/jelocabral)\
**Post date:** [June 26, 2020, 6:40pm UTC](https://discuss.elastic.co/t/send-linux-windows-networkdevices-logs-to-elastic-siem/238903/1 "2020-06-26T18:40:09Z")

</div>

Dear people, I have an ELK server 7.8.0.

I'm using the SIEM in order to see and monitor netflow and beats data.

But now I want to add every syslog messages from Linux, Windows and Network Devices (Cisco and much more). All these logs will be sent to an independent index, and I want to add it to the SIEM default indices in order to let the SIEM search for data there.

Is it possible to receive syslog data from different platforms so SIEM can loook for events on them?

Is it better to use filebeat with syslog module or logstash with syslog input to reach my objectve? Please send me a howto URL if you can.

Thanking in advance !!!

---

<div class="post-metadata">

**Author:** ![Andrew\_G](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andrew_g/32/49178_2.png) [@Andrew\_G](https://discuss.elastic.co/u/Andrew_G)\
**Post date:** [June 26, 2020, 10:40pm UTC](https://discuss.elastic.co/t/send-linux-windows-networkdevices-logs-to-elastic-siem/238903/2 "2020-06-26T22:40:06Z")

</div>

Hi @jelocabral!

> Is it possible to receive syslog data from different platforms so SIEM can loook for events on them?

Yes, it's possible to configure Filebeat as a Syslog receiver, as documented here: [Syslog input | Filebeat Reference [8.11] | Elastic](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-input-syslog.html)

That said, given your statement:

> I want to add every syslog messages from Linux, Windows and Network Devices (Cisco and much more)

You will have a better experience if you ingest the data from the hosts themselves:

- For example, the Linux data via the [Filebeat System module](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-system.html) and [Auditbeat](https://www.elastic.co/guide/en/beats/auditbeat/current/index.html)
- The Windows data via [Winlogbeat](https://www.elastic.co/guide/en/beats/winlogbeat/current/index.html) and [Auditbeat](https://www.elastic.co/guide/en/beats/auditbeat/current/index.html)
- The Cisco data via the [Filebeat Cisco module](https://www.elastic.co/guide/en/beats/filebeat/current/filebeat-module-cisco.html)

> Is it better to use filebeat with syslog module or logstash with syslog input to reach my objectve?

It's better to use the Beats described above (as opposed to just using Logstash). The data collected by Beats will automatically be available in the SIEM app.

One of the many reasons using Beats is a better option is that its modules will ensure the logs are parsed semantically, to extract meaningful data from the raw logs. For example, Beats will extract the process ID from raw logs representing process creation events, and map the process ID to the [`process.pid`](https://www.elastic.co/guide/en/ecs/current/ecs-process.html) field in the [Elastic Common Schema (ECS)](https://www.elastic.co/blog/introducing-the-elastic-common-schema).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 24, 2020, 10:40pm UTC](https://discuss.elastic.co/t/send-linux-windows-networkdevices-logs-to-elastic-siem/238903/3 "2020-07-24T22:40:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
