# Syslog output plugin and dynamic values

**URL:** <https://discuss.elastic.co/t/syslog-output-plugin-and-dynamic-values/24732>\
**Category:** Logstash\
**Created:** [July 1, 2015, 2:35pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-and-dynamic-values/24732 "2015-07-01T14:35:15Z")\
**Posts on this page:** 8\
**Page:** 1

<div class="post-metadata">

**Author:** ![incogniro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incogniro/32/5875_2.png) [@incogniro](https://discuss.elastic.co/u/incogniro)\
**Post date:** [July 1, 2015, 2:35pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-and-dynamic-values/24732/1 "2015-07-01T14:35:15Z")

</div>

Is there a way to use fields with this plugin in much the same ways as the File or Elasticsearch output plugin?

**The following does not work:**

```
		syslog {
			host => "10.10.10.1"
			port => 12543
			protocol	=> "tcp"
			facility => "user-level"
			severity => "%{loglevel}"
			appname => "%{zone}-%{container}"
			sourcehost	=> "%{host}"
			procid => "%{bundle}"
			msgid => "csms"
		}

```

**The result is:**

Invalid setting for syslog output plugin:

output {  
syslog {  
# This setting must be a ["emergency", "alert", "critical", "error", "warning", "notice", "informational", "debug"]  
# Expected one of ["emergency", "alert", "critical", "error", "warning", "notice", "informational", "debug"], got ["%{loglevel}"]  
severity =\> "%{loglevel}"  
...  
}  
} {:level=\>:error}

**However this does work:**

```
	elasticsearch {
		host => localhost
		index => "logstash-%{type}-%{host}-%{+YYYY.MM.dd}"
		document_id => "%{timestamp}"
	}
```

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 1, 2015, 10:10pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-and-dynamic-values/24732/2 "2015-07-01T22:10:44Z")

</div>

The configuration parameters where you can use `%{varname}` interpolation depends on the particular plugin and parameter and it's unfortunately not documented. When in doubt I read the code to find out. The parameter must be accessed with `event.sprintf(@name_of_param)` for it to work.

---

<div class="post-metadata">

**Author:** ![incogniro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incogniro/32/5875_2.png) [@incogniro](https://discuss.elastic.co/u/incogniro)\
**Post date:** [July 2, 2015, 7:35am UTC](https://discuss.elastic.co/t/syslog-output-plugin-and-dynamic-values/24732/3 "2015-07-02T07:35:35Z")

</div>

Thanks Magnus.

---

<div class="post-metadata">

**Author:** ![incogniro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incogniro/32/5875_2.png) [@incogniro](https://discuss.elastic.co/u/incogniro)\
**Post date:** [July 2, 2015, 10:34am UTC](https://discuss.elastic.co/t/syslog-output-plugin-and-dynamic-values/24732/4 "2015-07-02T10:34:08Z")

</div>

Magnus, I gave that a try:

```
			syslog {
				host => "10.10.1.1"
				port => 11122
				protocol	=> "tcp"
				facility => "user-level"
				severity => event.sprintf(@loglevel)
				appname => "fuse"
				sourcehost	=> event.sprintf(@host)
				procid => event.sprintf(@bundle)
				msgid => "csms"
			}

```

and receive the following:

λ csms  
io/console not supported; tty will not be manipulated  
Error: Expected one of #, {, } at line 246, column 24 (byte 6541) after output {  
if "\_grokparsefailure" in [tags] {  
if [type] =='karaf' {  
if [service] {  
file {  
path =\> "C:/Source/github/csms-dev-env/.misc/logs/fuse/%{type}-%{zone}-%{container}-failed-%{+YYYY-MM-dd}.log"  
}  
} else {  
file {  
path =\> "C:/Source/github/csms-dev-env/.misc/logs/fuse/%{type}-%{container}-failed-%{+YYYY-MM-dd}.log"  
}  
}  
} else {  
file {  
path =\> "C:/Source/github/csms-dev-env/.misc/logs/%{type}-failed-%{+YYYY-MM-dd}.log"  
}  
}  
}

```
    stdout {                                                                                                                                       
            codec => rubydebug                                                                                                                     
    }                                                                                                                                              
                                                                                                                                                   
                            syslog {                                                                                                               
                                    host => "10.10.1.1"                                                                                
                                    port => 11122                                                                                       
                                    protocol => "tcp"                                                                                       
                                    facility => "user-level"                                                                                
                                    severity => event                                                                                       

```

You may be interested in the '--configtest' flag which you can  
use to validate logstash's configuration before you choose  
to restart a running system.

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 2, 2015, 1:55pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-and-dynamic-values/24732/5 "2015-07-02T13:55:37Z")

</div>

Oh, sorry. That's not what I meant. It's the source code that must contain `event.sprintf()`. If it doesn't you can't use `%{varname}` references. I mentioned `event.sprintf()` because it's basically the only way to figure out whether it's supported for a particular field. You can't use it in configuration files.

---

<div class="post-metadata">

**Author:** ![incogniro](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/incogniro/32/5875_2.png) [@incogniro](https://discuss.elastic.co/u/incogniro)\
**Post date:** [July 2, 2015, 3:29pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-and-dynamic-values/24732/6 "2015-07-02T15:29:24Z")

</div>

Magnus, I've checked the code and event.sprintf() is used on the majority of the fields and I even used the source from [https://github.com/logstash-plugins/logstash-output-syslog/pull/4](https://github.com/logstash-plugins/logstash-output-syslog/pull/4) for complete support and the plugin still does not allow interpolation!!

---

<div class="post-metadata">

**Author:** ![magnusbaeck](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/magnusbaeck/32/44943_2.png) [@magnusbaeck](https://discuss.elastic.co/u/magnusbaeck)\
**Post date:** [July 2, 2015, 7:44pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-and-dynamic-values/24732/7 "2015-07-02T19:44:11Z")

</div>

The code looks right. Are you sure you managed to install and use the patched plugin? You can easily add a logging statement to be 100% sure.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 6, 2017, 5:35am UTC](https://discuss.elastic.co/t/syslog-output-plugin-and-dynamic-values/24732/8 "2017-07-06T05:35:42Z")

</div>


