# Sending Rsyslog data to logstash

**URL:** <https://discuss.elastic.co/t/sending-rsyslog-data-to-logstash/249066>\
**Category:** Logstash\
**Created:** [September 18, 2020, 7:15am UTC](https://discuss.elastic.co/t/sending-rsyslog-data-to-logstash/249066 "2020-09-18T07:15:34Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [September 18, 2020, 7:15am UTC](https://discuss.elastic.co/t/sending-rsyslog-data-to-logstash/249066/1 "2020-09-18T07:15:34Z")

</div>

I've configured two linux server for sending client rsyslog data to server.The server is receiving messages from client and i've installed elk service on server side now i want to send the rsyslog data (which the server was receiving) to logstash. earlier i was able to sent the data through filebeat.The filebeat was installed on the server side which then sent to logstash now i want to use syslog input but no index is created

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [September 22, 2020, 5:12am UTC](https://discuss.elastic.co/t/sending-rsyslog-data-to-logstash/249066/2 "2020-09-22T05:12:03Z")

</div>

I've configure rsyslog server logs are coming at the server side

```auto
input {
tcp {
port => 10514
}
}
output {
elasticsearch 
{
hosts => "localhost:9200"
index => "client-syslog-%{+YYYY.MM.dd}"
} }

```

the rsyslog logs are coming on `/var/log/remote/server/`(server side)  
no index is created in kibana.  
I also tried this

```auto
input {
syslog {
port => 10514
}
}

```

nothing works

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [September 23, 2020, 4:50am UTC](https://discuss.elastic.co/t/sending-rsyslog-data-to-logstash/249066/3 "2020-09-23T04:50:26Z")

</div>

can anyone tell me the solution of it?

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [September 24, 2020, 7:29am UTC](https://discuss.elastic.co/t/sending-rsyslog-data-to-logstash/249066/4 "2020-09-24T07:29:48Z")

</div>

hey @warkolm can you please help me

---

<div class="post-metadata">

**Author:** ![jfs1](https://avatars.discourse-cdn.com/v4/letter/j/439d5e/32.png) [@jfs1](https://discuss.elastic.co/u/jfs1)\
**Post date:** [September 24, 2020, 12:09pm UTC](https://discuss.elastic.co/t/sending-rsyslog-data-to-logstash/249066/5 "2020-09-24T12:09:54Z")

</div>

Probably, your best option is to use logstash as a syslog receiver.

> input {  
> udp {  
> id =\> "syslogUdp10514"  
> port =\> 10514  
> }  
> }

Then redirect syslog traffic to logstash through iptables :

> iptables -A PREROUTING -p udp -m udp --dport 514 -j REDIRECT --to-ports 10514

That way, your server's syslog wil continue working as usual, but traffic from other servers and adressed to UDP/514 (syslog standard) will be re-routed to your logstash instance.

---

<div class="post-metadata">

**Author:** ![Aniket\_Pant](https://avatars.discourse-cdn.com/v4/letter/a/77aa72/32.png) [@Aniket\_Pant](https://discuss.elastic.co/u/Aniket_Pant)\
**Post date:** [September 30, 2020, 2:08am UTC](https://discuss.elastic.co/t/sending-rsyslog-data-to-logstash/249066/6 "2020-09-30T02:08:53Z")

</div>

Hey @jfs1 thank you  
The logstash is receiving all the logs from syslog but it is not receiving boot logs

```auto

local7.* action(type="omfwd"
     queue.type="linkedlist"
      queue.filename="example_fwd"
      action.resumeRetryCount="-1"
      queue.saveOnShutdown="on"
      target="192.168.0.133" port="10514" protocol="udp"
     )

```

I am able to received authpriv.\* logs and daemon logs but not boot logs

---

<div class="post-metadata">

**Author:** ![jfs1](https://avatars.discourse-cdn.com/v4/letter/j/439d5e/32.png) [@jfs1](https://discuss.elastic.co/u/jfs1)\
**Post date:** [October 27, 2020, 7:25am UTC](https://discuss.elastic.co/t/sending-rsyslog-data-to-logstash/249066/7 "2020-10-27T07:25:26Z")

</div>

I guess you are referring to linux logs.  
Boot logs are not using the same path through rsyslog than other logs. Indeed, they are generated before the network is set up. I guess that your best option is to use a log file shipper (i.e. filebeat) instead of logstash for those logs.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [November 24, 2020, 7:25am UTC](https://discuss.elastic.co/t/sending-rsyslog-data-to-logstash/249066/8 "2020-11-24T07:25:29Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
