# Syslog configuration output

**URL:** <https://discuss.elastic.co/t/syslog-configuration-output/61522>\
**Category:** Logstash\
**Created:** [September 26, 2016, 4:04pm UTC](https://discuss.elastic.co/t/syslog-configuration-output/61522 "2016-09-26T16:04:55Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![ruzzetto](https://avatars.discourse-cdn.com/v4/letter/r/d9b06d/32.png) [@ruzzetto](https://discuss.elastic.co/u/ruzzetto)\
**Post date:** [September 26, 2016, 4:04pm UTC](https://discuss.elastic.co/t/syslog-configuration-output/61522/1 "2016-09-26T16:04:55Z")

</div>

Hi All,  
i'm a newbie of elastic world and i'm trying to grab some remote syslog logs to visualize them on kibana. I setup logstash with a configuration file like this:  
input {  
tcp {  
port =\> 514  
type =\> syslog  
}  
udp {  
port =\> 514  
type =\> syslog  
}  
}

filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])  
?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

output {  
elasticsearch { hosts =\> ["localhost:9200"] }  
stdout { codec =\> rubydebug }  
}

ELK stack is installed on ubuntu server and if i start the service with "service logstash start" it seems to go wrong. Following some guides on internet i tried to run the daemon with the option -f and specify configuration file. In this case i can see syslog messagges via CLI but i don't know how to pass them to ES.

Is it the configuration pasted wrong?  
Thanks a lot!

Fabio

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [September 26, 2016, 7:43pm UTC](https://discuss.elastic.co/t/syslog-configuration-output/61522/2 "2016-09-26T19:43:09Z")

</div>

"It seems to go wrong" is not a useful problem description. Please consult the Logstash logs to get more information about what's up.

In this particular case the problem is most likely that Logstash can't listen on port 514 (or any other port \< 1024) unless it's run as root or if you use one of the workarounds that are available (this is not specific to Logstash so you should find plenty of hints on e.g. StackOverflow).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 4:36am UTC](https://discuss.elastic.co/t/syslog-configuration-output/61522/3 "2017-07-06T04:36:49Z")

</div>


