# Sending logs to syslog using logstash

**URL:** <https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952>\
**Category:** Logstash\
**Created:** [June 1, 2023, 10:21am UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952 "2023-06-01T10:21:45Z")\
**Posts on this page:** 18\
**Page:** 1

<div class="post-metadata">

**Author:** ![mariya](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@mariya](https://discuss.elastic.co/u/mariya)\
**Post date:** [June 1, 2023, 10:21am UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/1 "2023-06-01T10:21:45Z")

</div>

I installed winlogbeat and Logstash on my WInodows and I want to send logs to Logstash that will forward the logs to pfSense,I mean using Logstash as an aggregator with the _logstash-output-tcp_ to send events to Syslog. any idea how can I do it ?

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [June 5, 2023, 8:13pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/2 "2023-06-05T20:13:59Z")

</div>

Hi @mariya,

How will pfSense accept the data? Through syslog? You'd basically configure logstash to read all the inputs you want and then setup the right outputs. Logstash supports syslog and tcp as [outputs](https://www.elastic.co/guide/en/logstash/current/output-plugins.html) so it is probably possible.

---

<div class="post-metadata">

**Author:** ![mariya](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@mariya](https://discuss.elastic.co/u/mariya)\
**Post date:** [June 6, 2023, 10:22am UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/4 "2023-06-06T10:22:58Z")

</div>

Is this configuration correct  
 ![image](https://us1.discourse-cdn.com/elastic/original/3X/3/8/382d570c468248ead6139a10262123dfb9613f46.png)

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [June 6, 2023, 1:06pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/5 "2023-06-06T13:06:29Z")

</div>

It looks reasonable. If you are able to paste the configuration as text that makes it easier for me to work with. Does logstash start up without throwing errors about the configuration file? You can also verify specific files with:

```auto
logstash -f <path_config_file> -t

```

If everything looks good you'll see it say: "Configuration OK".

---

<div class="post-metadata">

**Author:** ![mariya](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@mariya](https://discuss.elastic.co/u/mariya)\
**Post date:** [June 6, 2023, 1:22pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/6 "2023-06-06T13:22:56Z")

</div>

here is the configuration:

```auto
input {
  beats {
    port => 5044
  }
}
filter {
  grok {
   paterns_dir =>["/etc/logstash/patter"]
   match => {"message"=> "%{IPORHOST:clientip} %{NGUSER:ident} %{NGUSER:auth} \[%{HTTPDATE:timestamp}\"%{WORD:verb} %{URIPATHPARAM:request}
   HTTP/%{NUMBER:httpversion}\" %NUMBER:response}"
}
   }
output {
  syslog {
    hosts => "192.168.2.250"
    port => 514
    protocol => "tcp"
  }
}

```

and the output of the command `logstash -f <path_config_file> -t`

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/a/9/a97edfb4d3c5d78ded998c8d6f936307818fe9ed.png)

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [June 6, 2023, 1:29pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/7 "2023-06-06T13:29:47Z")

</div>

Ok, looks like syslog output plugin isn't installed but can be installed easily as documented [here](https://www.elastic.co/guide/en/logstash/8.7/plugins-outputs-syslog.html#_installation_50).

---

<div class="post-metadata">

**Author:** ![mariya](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@mariya](https://discuss.elastic.co/u/mariya)\
**Post date:** [June 6, 2023, 2:03pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/8 "2023-06-06T14:03:17Z")

</div>

I installed syslog output plugin:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/1/9/19131711ab408bed61e1644686922e40a3c94071.png)

---

<div class="post-metadata">

**Author:** ![mariya](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@mariya](https://discuss.elastic.co/u/mariya)\
**Post date:** [June 6, 2023, 2:03pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/9 "2023-06-06T14:03:53Z")

</div>

But I still have the same problem:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/9/7/97e8d0967ae84038548dfd4b2690a131fcd3019c.png)  
Sorry to bother you but I'm stuck with this

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [June 6, 2023, 2:10pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/10 "2023-06-06T14:10:53Z")

</div>

No problem, so it actually looks like a different problem that is still causing it to ultimately fail. Can you paste the whole error message as text please. Images are really hard for us to work with.

---

<div class="post-metadata">

**Author:** ![mariya](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@mariya](https://discuss.elastic.co/u/mariya)\
**Post date:** [June 6, 2023, 2:23pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/11 "2023-06-06T14:23:07Z")

</div>

here is the whole error message:

```auto
"Using bundled JDK: c:\Program Files\Logstash\logstash-8.7.1\jdk\bin\java.exe"
Sending Logstash logs to c:/Program Files/Logstash/logstash-8.7.1/logs which is now configured via log4j2.properties
[2023-06-06T15:20:52,345][INFO][logstash.runner] Log4j configuration path used is: c:\Program Files\Logstash\logstash-8.7.1\config\log4j2.properties
[2023-06-06T15:20:52,423][WARN][logstash.runner] The use of JAVA_HOME has been deprecated. Logstash 8.0 and later ignores JAVA_HOME and uses the bundled JDK. Running Logstash with the bundled JDK is recommended. The bundled JDK has been verified to work with each specific version of Logstash, and generally provides best performance and reliability. If you have compelling reasons for using your own JDK (organizational-specific compliance requirements, for example), you can configure LS_JAVA_HOME to use that version instead.
[2023-06-06T15:20:52,423][INFO][logstash.runner] Starting Logstash {"logstash.version"=>"8.7.1", "jruby.version"=>"jruby 9.3.10.0 (2.6.8) 2023-02-01 107b2e6697 OpenJDK 64-Bit Server VM 17.0.7+7 on 17.0.7+7 +indy +jit [x86_64-mswin32]"}
[2023-06-06T15:20:52,444][INFO][logstash.runner] JVM bootstrap flags: [-Xms1g, -Xmx1g, -Djava.awt.headless=true, -Dfile.encoding=UTF-8, -Djruby.compile.invokedynamic=true, -XX:+HeapDumpOnOutOfMemoryError, -Djava.security.egd=file:/dev/urandom, -Dlog4j2.isThreadContextMapInheritable=true, -Djruby.regexp.interruptible=true, -Djdk.io.File.enableADS=true, --add-exports=jdk.compiler/com.sun.tools.javac.api=ALL-UNNAMED, --add-exports=jdk.compiler/com.sun.tools.javac.file=ALL-UNNAMED, --add-exports=jdk.compiler/com.sun.tools.javac.parser=ALL-UNNAMED, --add-exports=jdk.compiler/com.sun.tools.javac.tree=ALL-UNNAMED, --add-exports=jdk.compiler/com.sun.tools.javac.util=ALL-UNNAMED, --add-opens=java.base/java.security=ALL-UNNAMED, --add-opens=java.base/java.io=ALL-UNNAMED, --add-opens=java.base/java.nio.channels=ALL-UNNAMED, --add-opens=java.base/sun.nio.ch=ALL-UNNAMED, --add-opens=java.management/sun.management=ALL-UNNAMED]
[2023-06-06T15:20:52,678][WARN][logstash.config.source.multilocal] Ignoring the 'pipelines.yml' file because modules or command line options are specified
[2023-06-06T15:20:57,416][ERROR][logstash.agent] Failed to execute action {:action=>LogStash::PipelineAction::Create/pipeline_id:main, :exception=>"LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n], \"#\", \"=>\" at line 17, column 10 (byte 420) after filter {\n grok {\n paterns_dir =>[\"/etc/logstash/patter\"]\n match => {\"message\"=> \"%{IPORHOST:clientip} %{NGUSER:ident} %{NGUSER:auth} \\[%{HTTPDATE:timestamp}\\\"%{WORD:verb} %{URIPATHPARAM:request}\n HTTP/%{NUMBER:httpversion}\\\" %NUMBER:response}\"\n}\n }\noutput {\n syslog ", :backtrace=>["C:/Program Files/Logstash/logstash-8.7.1/logstash-core/lib/logstash/compiler.rb:32:in `compile_imperative'", "org/logstash/execution/AbstractPipelineExt.java:239:in `initialize'", "org/logstash/execution/AbstractPipelineExt.java:173:in `initialize'", "C:/Program Files/Logstash/logstash-8.7.1/logstash-core/lib/logstash/java_pipeline.rb:48:in `initialize'", "org/jruby/RubyClass.java:911:in `new'", "C:/Program Files/Logstash/logstash-8.7.1/logstash-core/lib/logstash/pipeline_action/create.rb:50:in `execute'", "C:/Program Files/Logstash/logstash-8.7.1/logstash-core/lib/logstash/agent.rb:386:in `block in converge_state'"]}
[2023-06-06T15:20:57,996][INFO][logstash.agent] Successfully started Logstash API endpoint {:port=>9600, :ssl_enabled=>false}
[2023-06-06T15:20:58,091][INFO][logstash.runner] Logstash shut down.
[2023-06-06T15:20:58,123][FATAL][org.logstash.Logstash] Logstash stopped processing because of an error: (SystemExit) exit
org.jruby.exceptions.SystemExit: (SystemExit) exit
        at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:790) ~[jruby.jar:?]
        at org.jruby.RubyKernel.exit(org/jruby/RubyKernel.java:753) ~[jruby.jar:?]
        at c_3a_.Program_20_Files.Logstash.logstash_minus_8_dot_7_dot_1.lib.bootstrap.environment.<main>(c:\Program Files\Logstash\logstash-8.7.1\lib\bootstrap\environment.rb:91) ~[?:?]

```

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [June 6, 2023, 4:13pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/12 "2023-06-06T16:13:59Z")

</div>

> [@mariya](#):
>
> ```auto
> [2023-06-06T15:20:58,123][FATAL][org.logstash.Logstash] Logstash stopped processing because of an error: (SystemExit) exit
> org.jruby.exceptions.SystemExit: (SystemExit) exit
> 
> ```

For this kind of error you need to check in the system log for any hint why the service cannot start, look in `/var/log/messages` or `/var/log/syslog`.

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [June 6, 2023, 6:58pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/13 "2023-06-06T18:58:10Z")

</div>

I think you need to move the quote to the other side of the bracket on "match" line:

```auto
match => {"message"=> "%{IPORHOST:clientip} %{NGUSER:ident} %{NGUSER:auth} \[%{HTTPDATE:timestamp}\"%{WORD:verb} %{URIPATHPARAM:request} HTTP/%{NUMBER:httpversion}\" %NUMBER:response"}

```

---

<div class="post-metadata">

**Author:** ![mariya](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@mariya](https://discuss.elastic.co/u/mariya)\
**Post date:** [June 7, 2023, 9:34am UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/14 "2023-06-07T09:34:06Z")

</div>

Same error I tried to change all the filter:

```auto
filter {
    grok {
        match => { "message" => "%{COMBINEDAPACHELOG}" }
    }

    date {
        match => ["timestamp" , "dd/MMM/yyyy:HH:mm:ss Z"]
    }

    mutate {
        convert => {
            "response" => "integer"
            "bytes" => "integer"
        }
    }
}

```

I think the problem is not in the syntax

---

<div class="post-metadata">

**Author:** ![mariya](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@mariya](https://discuss.elastic.co/u/mariya)\
**Post date:** [June 7, 2023, 9:39am UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/15 "2023-06-07T09:39:18Z")

</div>

I'm using Windows I think `/var/log/messages` and `/var/log/syslog` work on Unix so I found that the equivalent of them is Event Viewer:

 ![image](https://us1.discourse-cdn.com/elastic/original/3X/2/1/21abc994e5600e07712ff05069ed68e4ee6576ad.png)

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [June 8, 2023, 11:49am UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/16 "2023-06-08T11:49:12Z")

</div>

> [@mariya](#):
>
> `LogStash::ConfigurationError", :message=>"Expected one of [\\t\\r\\n]`

It might not be a syntax error, but the error quoted above is what led me to believe there was something off. If it is logging to the event viewer can you provide the relevant logstash logs? There isn't much we can do with a screenshot of event viewer.

---

<div class="post-metadata">

**Author:** ![mariya](https://avatars.discourse-cdn.com/v4/letter/m/c67d28/32.png) [@mariya](https://discuss.elastic.co/u/mariya)\
**Post date:** [June 8, 2023, 1:17pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/17 "2023-06-08T13:17:47Z")

</div>

I wanted to inform you that despite my exhaustive efforts, none of the attempted solutions resolved the issues I was facing. As a result, I was compelled to make significant changes to my topology and configuration. I appreciate your valuable time and support throughout this process. Thank you so much.

---

<div class="post-metadata">

**Author:** ![Wave](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/wave/32/117242_2.png) [@Wave](https://discuss.elastic.co/u/Wave)\
**Post date:** [June 9, 2023, 2:43pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/18 "2023-06-09T14:43:43Z")

</div>

Ok, sorry to hear that, and that we weren't able to get this figured out.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 7, 2023, 2:44pm UTC](https://discuss.elastic.co/t/sending-logs-to-syslog-using-logstash/334952/19 "2023-07-07T14:44:38Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
