# Sending log data from rsyslog to logstash

**URL:** <https://discuss.elastic.co/t/sending-log-data-from-rsyslog-to-logstash/298765>\
**Category:** Logstash\
**Created:** [March 3, 2022, 4:39pm UTC](https://discuss.elastic.co/t/sending-log-data-from-rsyslog-to-logstash/298765 "2022-03-03T16:39:44Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Khammassi\_HoussemEdd](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/khammassi_houssemedd/32/101568_2.png) [@Khammassi\_HoussemEdd](https://discuss.elastic.co/u/Khammassi_HoussemEdd)\
**Post date:** [March 3, 2022, 4:39pm UTC](https://discuss.elastic.co/t/sending-log-data-from-rsyslog-to-logstash/298765/1 "2022-03-03T16:39:44Z")

</div>

i wanted to know whether it's a best practice to send log data DIRECTLY with rsyslog into logstash ??  
or is it better to send data from rsyslog to another rsyslog server and and then make logstash operate on this data received by rsyslog ??  
i mean is this strategy pointed in this article [how-to-centralize-logs-with-rsyslog-logstash-and-elasticsearch-on-ubuntu-14-04](https://www.elastic.co/blog/how-to-centralize-logs-with-rsyslog-logstash-and-elasticsearch-on-ubuntu-14-04), would be the best option ?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [March 31, 2022, 4:40pm UTC](https://discuss.elastic.co/t/sending-log-data-from-rsyslog-to-logstash/298765/2 "2022-03-31T16:40:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
