# SYSLOG-NG, Filebeat-Logstash-elasticsearch-Kibana - Suggestion!

**URL:** <https://discuss.elastic.co/t/syslog-ng-filebeat-logstash-elasticsearch-kibana-suggestion/82451>\
**Category:** Elasticsearch\
**Created:** [April 14, 2017, 11:35pm UTC](https://discuss.elastic.co/t/syslog-ng-filebeat-logstash-elasticsearch-kibana-suggestion/82451 "2017-04-14T23:35:00Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [April 14, 2017, 11:35pm UTC](https://discuss.elastic.co/t/syslog-ng-filebeat-logstash-elasticsearch-kibana-suggestion/82451/1 "2017-04-14T23:35:00Z")

</div>

Hi All

We have centralize logging server setup across network.

All the devices of Cisco or other devices send logs to SYSLOG-NG Server. they store in based on the IP and date and time as in folder.

Now i would like to take that date and create a easy dashboard and alert system.

I am thinking to 2 options here.

1. SYSLOG-NG --File-beat--Logstasg-ElasticSearch-Kibana
2. SYSLOG-NG --Logstasg-ElasticSearch-Kibana

What is your suggestion ?

Thank you  
R!

---

<div class="post-metadata">

**Author:** ![czanik](https://avatars.discourse-cdn.com/v4/letter/c/7cd45c/32.png) [@czanik](https://discuss.elastic.co/u/czanik)\
**Post date:** [April 15, 2017, 6:30pm UTC](https://discuss.elastic.co/t/syslog-ng-filebeat-logstash-elasticsearch-kibana-suggestion/82451/2 "2017-04-15T18:30:01Z")

</div>

You can also simplify it to syslog-ng -\> elasticsearch -\> Kibana: [https://www.balabit.com/blog/logging-to-elasticsearch-made-simple-with-syslog-ng/](https://www.balabit.com/blog/logging-to-elasticsearch-made-simple-with-syslog-ng/)

---

<div class="post-metadata">

**Author:** ![ramindia](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ramindia/32/32459_2.png) [@ramindia](https://discuss.elastic.co/u/ramindia)\
**Post date:** [April 15, 2017, 7:13pm UTC](https://discuss.elastic.co/t/syslog-ng-filebeat-logstash-elasticsearch-kibana-suggestion/82451/3 "2017-04-15T19:13:31Z")

</div>

Thank you, i have seen that post already,

As per my understanding, new syslog-ng can directly send the logs to elasticsearch.

But i am looking some normalization before sending to elasticsearch, due to heavy traffic from ASA or Checkpoint.

So i was thinking to use use logstash between, make sense ?

R!

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2017, 7:24pm UTC](https://discuss.elastic.co/t/syslog-ng-filebeat-logstash-elasticsearch-kibana-suggestion/82451/4 "2017-05-13T19:24:40Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
