# Syslog messages into logstash

**URL:** <https://discuss.elastic.co/t/syslog-messages-into-logstash/129425>\
**Category:** Logstash\
**Created:** [April 25, 2018, 7:32am UTC](https://discuss.elastic.co/t/syslog-messages-into-logstash/129425 "2018-04-25T07:32:22Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![artem33region](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@artem33region](https://discuss.elastic.co/u/artem33region)\
**Post date:** [April 25, 2018, 7:32am UTC](https://discuss.elastic.co/t/syslog-messages-into-logstash/129425/1 "2018-04-25T07:32:23Z")

</div>

Hi all!  
I want to get syslog messages from servers.  
I have installed ELK stack on CentOS 7 server.  
There is "no default index pattern"  
How i understand i need to install and configure "filebeat" on client server side.

I have a question. After ELK stack installed, i need to create "default index pattern"?

logstash config:  
filter {  
if [type] == "syslog" {  
grok {  
match =\> { "message" =\> "%{SYSLOGTIMESTAMP:syslog\_timestamp} %{SYSLOGHOST:syslog\_hostname} %{DATA:syslog\_program}(?:[%{POSINT:syslog\_pid}])?: %{GREEDYDATA:syslog\_message}" }  
add\_field =\> ["received\_at", "%{@timestamp}"]  
add\_field =\> ["received\_from", "%{host}"]  
}  
syslog\_pri { }  
date {  
match =\> ["syslog\_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]  
}  
}  
}

* * *

input {  
beats {  
port =\> 5044  
ssl =\> true  
ssl\_certificate =\> "/etc/pki/tls/certs/logstash-forwarder.crt"  
ssl\_key =\> "/etc/pki/tls/private/logstash-forwarder.key"  
}  
}

* * *

output {  
elasticsearch {  
hosts =\> ["localhost:9200"]  
sniffing =\> true  
manage\_template =\> false  
index =\> "%{[@metadata][beat]}-%{+YYYY.MM.dd}"  
document\_type =\> "%{[@metadata][type]}"  
}  
}

---

<div class="post-metadata">

**Author:** ![JKhondhu](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@JKhondhu](https://discuss.elastic.co/u/JKhondhu)\
**Post date:** [April 26, 2018, 10:45pm UTC](https://discuss.elastic.co/t/syslog-messages-into-logstash/129425/2 "2018-04-26T22:45:49Z")

</div>

[https://www.elastic.co/guide/en/kibana/current/tutorial-define-index.html](https://www.elastic.co/guide/en/kibana/current/tutorial-define-index.html)

---

<div class="post-metadata">

**Author:** ![artem33region](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@artem33region](https://discuss.elastic.co/u/artem33region)\
**Post date:** [April 27, 2018, 7:00am UTC](https://discuss.elastic.co/t/syslog-messages-into-logstash/129425/3 "2018-04-27T07:00:50Z")

</div>

Hello, thanks for your answer!  
I have read this tutorial, but in Kibana 6.X has not "Add New" button...  
How i understand, that button apper when i installed and setup for example filebeat on side client server?

---

<div class="post-metadata">

**Author:** ![JKhondhu](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@JKhondhu](https://discuss.elastic.co/u/JKhondhu)\
**Post date:** [April 27, 2018, 7:17am UTC](https://discuss.elastic.co/t/syslog-messages-into-logstash/129425/4 "2018-04-27T07:17:11Z")

</div>

Can you send me the output to `GET _cat/indices?v` ?

---

<div class="post-metadata">

**Author:** ![artem33region](https://avatars.discourse-cdn.com/v4/letter/a/f07891/32.png) [@artem33region](https://discuss.elastic.co/u/artem33region)\
**Post date:** [April 27, 2018, 7:27am UTC](https://discuss.elastic.co/t/syslog-messages-into-logstash/129425/5 "2018-04-27T07:27:37Z")

</div>

health status index uuid pri rep docs.count docs.deleted store.size pri.store.size  
green open .kibana 6CfpdIAbSvuG-wyoLyU3Dg 1 0 2 0 10.1kb 10.1kb  
yellow open logstash-2018.04.27 2VBsjn8eQX2cSStxj4fCKg 5 1 39 0 146.3kb 146.3kb

---

<div class="post-metadata">

**Author:** ![JKhondhu](https://avatars.discourse-cdn.com/v4/letter/j/ed655f/32.png) [@JKhondhu](https://discuss.elastic.co/u/JKhondhu)\
**Post date:** [April 27, 2018, 8:08am UTC](https://discuss.elastic.co/t/syslog-messages-into-logstash/129425/6 "2018-04-27T08:08:46Z")

</div>

So you do have a non system index called `logstash-2018.04.27` with 39 documents.

Go to Kibana discover and see the section that says `checking for index pattern` and you can add the logstash-\* pattern to start discovering the LS data.  
ref: [https://www.elastic.co/guide/en/kibana/current/tutorial-define-index.html](https://www.elastic.co/guide/en/kibana/current/tutorial-define-index.html)

As for filebeat you need to check why its not working, check that it is effectively sending to LS, at best have a look at the documents you have in the LS index first.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 25, 2018, 8:17am UTC](https://discuss.elastic.co/t/syslog-messages-into-logstash/129425/7 "2018-05-25T08:17:41Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
