# Shipping logs of system Linux with Filebeat and Logstash

**URL:** <https://discuss.elastic.co/t/shipping-logs-of-system-linux-with-filebeat-and-logstash/294137>\
**Category:** Logstash\
**Created:** [January 12, 2022, 9:35am UTC](https://discuss.elastic.co/t/shipping-logs-of-system-linux-with-filebeat-and-logstash/294137 "2022-01-12T09:35:05Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![Lynow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/lynow/32/98866_2.png) [@Lynow](https://discuss.elastic.co/u/Lynow)\
**Post date:** [January 12, 2022, 9:35am UTC](https://discuss.elastic.co/t/shipping-logs-of-system-linux-with-filebeat-and-logstash/294137/1 "2022-01-12T09:35:05Z")

</div>

Hello,

I am setting up a log monitoring architecture, for this I am using Opensearch and Kibana to collect all the data. The data is sent by Filebeat, which retrieves the logs from Wazuh (with different agents).

I then added Logstash, in order to have an additional filtering layer.  
However, when viewing data on Opensearch, the data is very poorly parsed.  
For example, during an alert displayed in the logs, I get this on OpenSearch :

 ![Capture d’écran 2022-01-11 171908](https://us1.discourse-cdn.com/elastic/original/3X/3/6/368c357c3d2c6460aeeb5e309337f998fc753c1a.png)

The alert is created by an agent located at a workstation, following an SSH connection request.

Here is the content of the Logstash configuration file. I tried to put filters, but it didn't change anything :

```auto
input {
    beats {
        port => 5044
        tags => "filebeat"
    }
}

filter {
        grok {
                match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GRE$
        }
        date {
                match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"] }
        mutate {
                convert => {
                "response" => "integer"
                "bytes" => "integer"
                }
        }
}

output {

        if "filebeat" in [tags] {
                opensearch {
                hosts => ["https://localhost:9200"]
                index => "wazuh-%{+YYYY.MM.dd}"
                user => "admin"
                password => "admin"
                ssl => true
                ssl_certificate_verification => false
                }
        }
        stdout { codec => rubydebug }
}

```

Does anyone have any idea how to do this?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 9, 2022, 9:35am UTC](https://discuss.elastic.co/t/shipping-logs-of-system-linux-with-filebeat-and-logstash/294137/2 "2022-02-09T09:35:14Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
