# Suggested pipline for rsyslog

**URL:** <https://discuss.elastic.co/t/suggested-pipline-for-rsyslog/290919>\
**Category:** Logstash\
**Created:** [December 3, 2021, 5:03pm UTC](https://discuss.elastic.co/t/suggested-pipline-for-rsyslog/290919 "2021-12-03T17:03:40Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![aqwserf](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/aqwserf/32/97341_2.png) [@aqwserf](https://discuss.elastic.co/u/aqwserf)\
**Post date:** [December 3, 2021, 5:03pm UTC](https://discuss.elastic.co/t/suggested-pipline-for-rsyslog/290919/1 "2021-12-03T17:03:40Z")

</div>

Hi everyone !

Quite new user to the ELK stack, and after reading a lot of docs/threads, I'd like some suggestions about my current situation.

I have a couple of SOHO router running Openwrt, a Proxmox server and a VPS. I'd like to centralize these type of logs:

- OpenWRT: syslog + fw (`--log-prefix` added)
- Proxmox: syslog
- VPS: syslog + fw (`--log-prefix` added) + nginx + fail2ban

As OpenWRT can't run filebeat, I have to rely on rsyslog (already configured). I'm able to view some rsyslog using [this](https://www.elastic.co/blog/how-to-centralize-logs-with-rsyslog-logstash-and-elasticsearch-on-ubuntu-14-04) tutorial (rsyslogd -\> logstash -\> Elasticsearch) but I was wondering there's an easier way (aka KISS) to do that.

I was thinking about at leat two solutions:

- using the syslog filebeat input module to gather syslog from OpenWRT, then Logstash to extract either syslog or iptables information and filebeat for Proxmox and VPS.
- using rsyslog to store every events locally and then using the adequate module to use the predefined dashboards.

What do you think ? Any other easy solutions ?

Thanks !

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 31, 2021, 5:04pm UTC](https://discuss.elastic.co/t/suggested-pipline-for-rsyslog/290919/2 "2021-12-31T17:04:23Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
