# Send logs from remote server on the same network

**URL:** <https://discuss.elastic.co/t/send-logs-from-remote-server-on-the-same-network/300052>\
**Category:** Elastic Observability\
**Created:** [March 18, 2022, 2:01pm UTC](https://discuss.elastic.co/t/send-logs-from-remote-server-on-the-same-network/300052 "2022-03-18T14:01:42Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![Arraso26](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/arraso26/32/103214_2.png) [@Arraso26](https://discuss.elastic.co/u/Arraso26)\
**Post date:** [March 18, 2022, 2:01pm UTC](https://discuss.elastic.co/t/send-logs-from-remote-server-on-the-same-network/300052/1 "2022-03-18T14:01:42Z")

</div>

Good, I want to send the logs from a server to this one but the logs don't arrive, I show you the files to see if you can help me.

**sudo cat /etc/logstash/conf.d/30-Elasticsearch-output.conf**

```auto
> output {
> elasticsearch {
> hosts => ["localhost:9200"]
> manage_template => false
> index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}"
> }
> }

```

**sudo cat /etc/logstash/conf.d/10-syslog-filter.conf**

```auto
> filter {
> if [fileset][module] == "system" {
> if [fileset][name] == "auth" {
> grok {
> match => { "message" => ["%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: %{DATA:[system][auth][ssh][event]} %{DATA:[system][auth][ssh][method]} for (invalid user )?%{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]} port %{NUMBER:[system][auth][ssh][port]} ssh2(: %{GREEDYDATA:[system][auth][ssh][signature]})?",
> "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: %{DATA:[system][auth][ssh][event]} user %{DATA:[system][auth][user]} from %{IPORHOST:[system][auth][ssh][ip]}",
> "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sshd(?:\[%{POSINT:[system][auth][pid]}\])?: Did not receive identification string from %{IPORHOST:[system][auth][ssh][dropped_ip]}",
> "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} sudo(?:\[%{POSINT:[system][auth][pid]}\])?: \s*%{DATA:[system][auth][user]} :( %{DATA:[system][auth][sudo][error]} ;)? TTY=%{DATA:[system][auth][sudo][tty]} ; PWD=%{DATA:[system][auth][sudo][pwd]} ; USER=%{DATA:[system][auth][sudo][user]} ; COMMAND=%{GREEDYDATA:[system][auth][sudo][command]}",
> "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} groupadd(?:\[%{POSINT:[system][auth][pid]}\])?: new group: name=%{DATA:system.auth.groupadd.name}, GID=%{NUMBER:system.auth.groupadd.gid}",
> "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} useradd(?:\[%{POSINT:[system][auth][pid]}\])?: new user: name=%{DATA:[system][auth][user][add][name]}, UID=%{NUMBER:[system][auth][user][add][uid]}, GID=%{NUMBER:[system][auth][user][add][gid]}, home=%{DATA:[system][auth][user][add][home]}, shell=%{DATA:[system][auth][user][add][shell]}$",
> "%{SYSLOGTIMESTAMP:[system][auth][timestamp]} %{SYSLOGHOST:[system][auth][hostname]} %{DATA:[system][auth][program]}(?:\[%{POSINT:[system][auth][pid]}\])?: %{GREEDYMULTILINE:[system][auth][message]}"] }
> pattern_definitions => {
> "GREEDYMULTILINE"=> "(.|\n)*"
> }
> remove_field => "message"
> }
> date {
> match => ["[system][auth][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
> }
> geoip {
> source => "[system][auth][ssh][ip]"
> target => "[system][auth][ssh][geoip]"
> }
> }
> else if [fileset][name] == "syslog" {
> grok {
> match => { "message" => ["%{SYSLOGTIMESTAMP:[system][syslog][timestamp]} %{SYSLOGHOST:[system][syslog][hostname]} %{DATA:[system][syslog][program]}(?:\[%{POSINT:[system][syslog][pid]}\])?: %{GREEDYMULTILINE:[system][syslog][message]}"] }
> pattern_definitions => { "GREEDYMULTILINE" => "(.|\n)*" }
> remove_field => "message"
> }
> date {
> match => ["[system][syslog][timestamp]", "MMM d HH:mm:ss", "MMM dd HH:mm:ss" ]
> }
> }
> }
> }

```

**ubuntukiba@ubuntukiba:~$ sudo cat /etc/logstash/conf.d/02-beats-input.conf**

```auto
> input {
> beats {
> port => 5044
> }
> }

```

**/etc/filebeat/filebeat.yml**

```auto
> output.logstash:
> # The Logstash hosts
> hosts: ["localhost:5044"]

```

**CLIENT**

```auto
> output.logstash:
> # The Logstash hosts
> hosts: ["192.168.14.78(THE SERVER):5044"]

```

---

<div class="post-metadata">

**Author:** ![FALEN](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/falen/32/82754_2.png) [@FALEN](https://discuss.elastic.co/u/FALEN)\
**Post date:** [March 22, 2022, 8:35am UTC](https://discuss.elastic.co/t/send-logs-from-remote-server-on-the-same-network/300052/2 "2022-03-22T08:35:22Z")

</div>

Hi @Arraso26

Did you tried disabling filter conf, maybe there is something wrong with your grok

```auto
mv /etc/logstash/conf.d/10-syslog-filter.conf /etc/logstash/conf.d/10-syslog-filter.disabled
systemctl restart logstash

```

And also please check debug log of filebeat agent installed on client, to see if it works properly/permission error on log file etc...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 4, 2022, 8:34am UTC](https://discuss.elastic.co/t/send-logs-from-remote-server-on-the-same-network/300052/3 "2022-11-04T08:34:43Z")

</div>


