# Syslog Multiple log entries in a single log

**URL:** https://discuss.elastic.co/t/syslog-multiple-log-entries-in-a-single-log/49823
**Category:** Logstash
**Created:** [May 11, 2016, 8:01pm UTC](https://discuss.elastic.co/t/syslog-multiple-log-entries-in-a-single-log/49823 "2016-05-11T20:01:50Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![davidhowell-tx](https://avatars.discourse-cdn.com/v4/letter/d/898d66/32.png) [@davidhowell-tx](https://discuss.elastic.co/u/davidhowell-tx)
#### Post date: [May 11, 2016, 8:01pm UTC](https://discuss.elastic.co/t/syslog-multiple-log-entries-in-a-single-log/49823/1 "2016-05-11T20:01:50Z")

</div>

I am using the Logstash Syslog input plugin to receive events from a single source. I've noticed that sometimes the message actually includes multiple log entries. I've seen up to 5 events in the message field of a single event in ElasticSearch with this setup. Does anyone have any tips to dealing with this type of issue? I'm considering trying out the TCP input next.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [July 6, 2017, 4:58am UTC](https://discuss.elastic.co/t/syslog-multiple-log-entries-in-a-single-log/49823/2 "2017-07-06T04:58:07Z")

</div>


