# Syslog forwarding question -\> Logstash (very basic)

**URL:** <https://discuss.elastic.co/t/syslog-forwarding-question-logstash-very-basic/127548>\
**Category:** Logstash\
**Created:** [April 10, 2018, 9:32pm UTC](https://discuss.elastic.co/t/syslog-forwarding-question-logstash-very-basic/127548 "2018-04-10T21:32:39Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [April 10, 2018, 9:32pm UTC](https://discuss.elastic.co/t/syslog-forwarding-question-logstash-very-basic/127548/1 "2018-04-10T21:32:39Z")

</div>

Hi there,

I'm a newbie.

I'd like to forward syslog messages to my ELK stack. So basically am I right to assume logstash is capable of receiving syslog messages and parsing them without sending to a syslog server first?

I forward syslog directly from my Cisco switch, remote log to ELK server ip UDP 5514.

On my ELK server:  
udp 0 0 0.0.0.0:5514 0.0.0.0:\*

My input file:

```
input {
udp {
port => 5514
type => "syslog"

```

my filter file:

```
filter {
if [type] == "syslog" {
grok {
match => { "message" => "%{SYSLOGLINE}" }
}
date {
match => ["timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
}
}
}

```

My output file:

```
output {
  elasticsearch {
      hosts => ["http://localhost:9200"]
      index => "syslog-%{+YYYY.MM.dd}"
      document_type => "system_logs"
  }
  stdout { codec => rubydebug }
}

```

when I search logstash log for incoming UDP:

[INFO][logstash.inputs.udp] Starting UDP listener {:address=\>"0.0.0.0:5514"}

So basically input logstash UDP 5514 and output to elasticsearch 9200.

Looks fine.

kibana runs on [http://localhost:5601](http://localhost:5601)

But doesn't seem to index my syslog messages. Is there a way to check if syslog messages are coming in at all?

---

<div class="post-metadata">

**Author:** ![Evesy](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/evesy/32/29520_2.png) [@Evesy](https://discuss.elastic.co/u/Evesy)\
**Post date:** [April 10, 2018, 10:44pm UTC](https://discuss.elastic.co/t/syslog-forwarding-question-logstash-very-basic/127548/2 "2018-04-10T22:44:20Z")

</div>

Hey Erik,

You're right that Logstash can receive syslog messages directly, using the syslog input, or tcp/udp inputs.

If you want to check stuff is definitely getting through the front door you could try the below on your Logstash nodes:

`tcpdump -A -i any dst port 5514`

Enabling additional logging on your UDP input might also give some visibility: [https://www.elastic.co/guide/en/logstash/current/logging.html#\_logging\_apis](https://www.elastic.co/guide/en/logstash/current/logging.html#_logging_apis)

---

<div class="post-metadata">

**Author:** ![anhlqn](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/anhlqn/32/5454_2.png) [@anhlqn](https://discuss.elastic.co/u/anhlqn)\
**Post date:** [April 10, 2018, 11:23pm UTC](https://discuss.elastic.co/t/syslog-forwarding-question-logstash-very-basic/127548/3 "2018-04-10T23:23:31Z")

</div>

> [@heskez](#):
>
> stdout { codec =\> rubydebug }

You already had this block which displays any events to the console (given that you are running Logstash from console) in additional to trying to index to ES, so if you don't see anything from the console, the logs are not arriving at Logstash.

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [April 11, 2018, 8:19am UTC](https://discuss.elastic.co/t/syslog-forwarding-question-logstash-very-basic/127548/4 "2018-04-11T08:19:46Z")

</div>

Hi Michael, thanks for your answer! I tried to see with TCPDUMP and syslog messages are coming in! What would be the next step?

I edited to debug this lines:

"logstash.inputs.udp" : "DEBUG",  
"logstash.outputs.elasticsearch" : "DEBUG",  
"logstash.outputs.stdout" : "DEBUG",

But where am I able to find the debug info?

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [April 11, 2018, 10:34am UTC](https://discuss.elastic.co/t/syslog-forwarding-question-logstash-very-basic/127548/5 "2018-04-11T10:34:07Z")

</div>

Well actually I ran logstash --debug too turn all debug on.  
Actually it looks fine. What else could I check?

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [April 11, 2018, 6:01pm UTC](https://discuss.elastic.co/t/syslog-forwarding-question-logstash-very-basic/127548/6 "2018-04-11T18:01:11Z")

</div>

When I run; /usr/share/logstash/bin/logstash --path.settings /etc/logstash --debug  
no syslog messages are appearing on the console.. so must be something wrong with input ?

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [April 11, 2018, 6:41pm UTC](https://discuss.elastic.co/t/syslog-forwarding-question-logstash-very-basic/127548/7 "2018-04-11T18:41:37Z")

</div>

When I run: [root@host-l01 ~]# curl 'localhost:9200/\_cat/indices?v'  
health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
close .watcher-history-7-2018.04.11 01Z34Tk8SoCWrrQj\_oFlYA  
green open .triggered\_watches dm4mpxy\_Q4GTwLJPVjQ7ng 1 0 0 0 15.5kb 15.5kb  
green open .watches n0HQZ2pKT4GTvfMHrOeo2g 1 0 6 0 32.9kb 32.9kb  
green open .monitoring-es-6-2018.04.11 GWH5uCuOQjGjdSkf22ZoUw 1 0 1839 12 1mb 1mb  
green open .security-6 ZXbp\_DODSouFZamobe3Wdg 1 0 3 0 9.8kb 9.8kb  
green open .monitoring-alerts-6 whBL9bysR7au2\_1bBSMtPQ 1 0 1 0 6.1kb 6.1kb

it doesn't seem to display an index from logstash or something that is increasing in values.

---

<div class="post-metadata">

**Author:** ![heskez](https://avatars.discourse-cdn.com/v4/letter/h/ecae2f/32.png) [@heskez](https://discuss.elastic.co/u/heskez)\
**Post date:** [April 11, 2018, 9:25pm UTC](https://discuss.elastic.co/t/syslog-forwarding-question-logstash-very-basic/127548/8 "2018-04-11T21:25:53Z")

</div>

Got it to work. Apparently there was a syntax error in my input file..  
corrected it, now all logstash and syslog indices show up.. 🙂

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 9, 2018, 9:26pm UTC](https://discuss.elastic.co/t/syslog-forwarding-question-logstash-very-basic/127548/9 "2018-05-09T21:26:12Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
