# Send log from rsyslog to ELK with X-PACK

**URL:** <https://discuss.elastic.co/t/send-log-from-rsyslog-to-elk-with-x-pack/89042>\
**Category:** Elasticsearch\
**Created:** [June 12, 2017, 12:57pm UTC](https://discuss.elastic.co/t/send-log-from-rsyslog-to-elk-with-x-pack/89042 "2017-06-12T12:57:47Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Izana](https://avatars.discourse-cdn.com/v4/letter/i/bc79bd/32.png) [@Izana](https://discuss.elastic.co/u/Izana)\
**Post date:** [June 12, 2017, 12:57pm UTC](https://discuss.elastic.co/t/send-log-from-rsyslog-to-elk-with-x-pack/89042/1 "2017-06-12T12:57:47Z")

</div>

Hello,

After installing X-PACK (necessary for Watcher and securing access to Kibana), my linux logs do not go back to ELK.

Indeed, before the installation of X-PACK, I had the following configuration on my Debian client:

/etc/rsyslog.d/rsyslog.conf

`*.* @192.168.1.1:5544`

This is the configuration on my ELK :  
/etc/logstash/conf.d/logstash\_lmpm\_linux.conf

```
input {
  syslog {
    port => "5544"
    type => "rsyslog"
  }
}

filter { }

output {
  if [type] == "rsyslog" {
    elasticsearch {
      hosts => ["192.168.1.1:9200"]
      index => "winlogbeat-%{+YYYY.MM.dd}"
    }
  }
}

```

Since installing X-PACK, I had to modify the winlogbeat.yml file on my client machines in order to add the elastic account and its password. I guess you have to do the same for a Linux. How can I do this?

Thank you for your answers.

---

<div class="post-metadata">

**Author:** ![Julien](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/julien/32/19688_2.png) [@Julien](https://discuss.elastic.co/u/Julien)\
**Post date:** [June 16, 2017, 8:49am UTC](https://discuss.elastic.co/t/send-log-from-rsyslog-to-elk-with-x-pack/89042/2 "2017-06-16T08:49:18Z")

</div>

Hi Alison,

You are correct in saying that once elasticsearch requires authentication, you will have to pass it when writing from logstash.  
Please follow the steps documented here to create a user and assign it a role with sufficient permissions and use it in the output section (or use an existing user with enough permissions):  
[https://www.elastic.co/guide/en/x-pack/current/logstash.html](https://www.elastic.co/guide/en/x-pack/current/logstash.html)

Also for informations on security, I would recommend this course which will cover roles, user creation and also securing elasticsearch : [https://www.elastic.co/training/x-pack-security](https://www.elastic.co/training/x-pack-security)  
Thanks  
Julien

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 14, 2017, 8:49am UTC](https://discuss.elastic.co/t/send-log-from-rsyslog-to-elk-with-x-pack/89042/3 "2017-07-14T08:49:26Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
