# Sending logs from logstash to syslog-ng

**URL:** <https://discuss.elastic.co/t/sending-logs-from-logstash-to-syslog-ng/104309>\
**Category:** Logstash\
**Created:** [October 17, 2017, 10:16pm UTC](https://discuss.elastic.co/t/sending-logs-from-logstash-to-syslog-ng/104309 "2017-10-17T22:16:57Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lakshman\_Mukkamalla](https://avatars.discourse-cdn.com/v4/letter/l/ce73a5/32.png) [@Lakshman\_Mukkamalla](https://discuss.elastic.co/u/Lakshman_Mukkamalla)\
**Post date:** [October 17, 2017, 10:16pm UTC](https://discuss.elastic.co/t/sending-logs-from-logstash-to-syslog-ng/104309/1 "2017-10-17T22:16:57Z")

</div>

Hi,  
I have a setup where i am able to send the logs from Log Files -\> Filebeat -\> Logstash -\> rsyslog server.  
But the customer has a syslog-ng as the server, have tried to work with the above pipeline with the logstash syslog output plugin but it is unable to send the logs to syslog-ng server. Would logstash syslog output plugin work with syslog-ng server or only rsyslog server?  
What i am looking for in short is Logstash -\> syslog-ng server.  
Any help is very much appreciated.

Thanks.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [October 18, 2017, 5:16am UTC](https://discuss.elastic.co/t/sending-logs-from-logstash-to-syslog-ng/104309/2 "2017-10-18T05:16:20Z")

</div>

Have you looked at the output's `rfc` option?

---

<div class="post-metadata">

**Author:** ![fekete\_robert](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/fekete_robert/32/23144_2.png) [@fekete\_robert](https://discuss.elastic.co/u/fekete_robert)\
**Post date:** [October 18, 2017, 7:06am UTC](https://discuss.elastic.co/t/sending-logs-from-logstash-to-syslog-ng/104309/3 "2017-10-18T07:06:17Z")

</div>

Hi, depending on the platform and the kind of processing you do with filebeat/logstash, you might not even need them, and can read the log messages with syslog-ng directly.

If you stick to Logstash, check the format it sends out the log messages - you'll need a matching source on the syslog-ng server. If logstash uses RFC3164 format (BSD-style syslog), use a network() source in syslog-ng. If it uses RFC5424, use a syslog() source.

HTH  
Robert

---

<div class="post-metadata">

**Author:** ![czanik](https://avatars.discourse-cdn.com/v4/letter/c/7cd45c/32.png) [@czanik](https://discuss.elastic.co/u/czanik)\
**Post date:** [October 30, 2017, 1:10pm UTC](https://discuss.elastic.co/t/sending-logs-from-logstash-to-syslog-ng/104309/4 "2017-10-30T13:10:24Z")

</div>

Hi,  
It seems to me, that logstash sends a new syslog header with the complete original message to syslog-ng:

> Oct 30 12:59:21 localhost.localdomain LOGSTASH[-]: Oct 30 08:59:20 localhost NetworkManager[770]: [1509368360.0101] ndisc[0x55f278312440,"eno16777736"]: complete-address: can't generate a new EUI-64 address

Could you share your logstash / rsyslog configuration?

---

<div class="post-metadata">

**Author:** ![czanik](https://avatars.discourse-cdn.com/v4/letter/c/7cd45c/32.png) [@czanik](https://discuss.elastic.co/u/czanik)\
**Post date:** [November 2, 2017, 12:15pm UTC](https://discuss.elastic.co/t/sending-logs-from-logstash-to-syslog-ng/104309/5 "2017-11-02T12:15:03Z")

</div>

Hi,  
Tested it a bit more and put together a quick blog on the topic: [https://www.balabit.com/blog/sending-logs-logstash-syslog-ng/](https://www.balabit.com/blog/sending-logs-logstash-syslog-ng/)  
I hope you find it useful.  
Peter

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 30, 2017, 12:15pm UTC](https://discuss.elastic.co/t/sending-logs-from-logstash-to-syslog-ng/104309/6 "2017-11-30T12:15:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
