# Syslog from Aruba Switches

**URL:** <https://discuss.elastic.co/t/syslog-from-aruba-switches/270543>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [April 19, 2021, 7:45am UTC](https://discuss.elastic.co/t/syslog-from-aruba-switches/270543 "2021-04-19T07:45:43Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![Peque](https://avatars.discourse-cdn.com/v4/letter/p/f475e1/32.png) [@Peque](https://discuss.elastic.co/u/Peque)\
**Post date:** [April 19, 2021, 7:45am UTC](https://discuss.elastic.co/t/syslog-from-aruba-switches/270543/1 "2021-04-19T07:45:43Z")

</div>

Hi Forum  
I've build my first ELK server - and have some incomming data - But I cannot make my Aruba 2530 Switches send the logfiles to elastic - and missing something somewhere.

On My Aruba switches - I set the following settings:

```auto
logging 10.102.62.3
logging facility syslog
logging severity info

```

On My Elasticsearch I have created the following file: /etc/logstash/conf.d/01.syslog.conf

```auto
input {
  udp {
    host => "127.0.0.1"
    port => 514
    codec => "json"
    type => "syslog"
  }
}

# The Filter pipeline stays empty here, no formatting is done. 
filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss.SSS", "MMM dd HH:mm:ss.SSS"]
      timezone => "UTC"
    }
  }
}

# Every single log will be forwarded to ElasticSearch. If you are using another port, you should specify it here.
output {
  if [type] == "syslog" {
    elasticsearch {
      hosts => ["127.0.0.1:9200"]
    }
  }
}

```

But I do not get any data from any switche - so somewhere I'm missing something here.  
Somehow I have an though that I'm missing creating the index ( But are able to see it in kibana . without any data inside. Can anyone see why and where my problem is here ???  
Thanks in advance

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 22, 2021, 1:33am UTC](https://discuss.elastic.co/t/syslog-from-aruba-switches/270543/2 "2021-04-22T01:33:18Z")

</div>

It's because u have the logstash input set to listen on `127.0.0.1` only. Set it to the correct interface ip or remove it and it defaults to `0.0.0.0`.

---

<div class="post-metadata">

**Author:** ![legoguy1000](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/legoguy1000/32/54301_2.png) [@legoguy1000](https://discuss.elastic.co/u/legoguy1000)\
**Post date:** [April 22, 2021, 1:36am UTC](https://discuss.elastic.co/t/syslog-from-aruba-switches/270543/3 "2021-04-22T01:36:30Z")

</div>

Also there is no Filebeat module for Aruba logs. I'd open a new module request issue on GitHub to get one added for the future.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 20, 2021, 3:37am UTC](https://discuss.elastic.co/t/syslog-from-aruba-switches/270543/4 "2021-05-20T03:37:20Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
