# Syslog output plugin :number type input parametrization

**URL:** <https://discuss.elastic.co/t/syslog-output-plugin-number-type-input-parametrization/322905>\
**Category:** Logstash\
**Created:** [January 11, 2023, 10:25am UTC](https://discuss.elastic.co/t/syslog-output-plugin-number-type-input-parametrization/322905 "2023-01-11T10:25:26Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![arirajamaki](https://avatars.discourse-cdn.com/v4/letter/a/a88e57/32.png) [@arirajamaki](https://discuss.elastic.co/u/arirajamaki)\
**Post date:** [January 11, 2023, 10:25am UTC](https://discuss.elastic.co/t/syslog-output-plugin-number-type-input-parametrization/322905/1 "2023-01-11T10:25:26Z")

</div>

Hello Community,

I'm in trouble with my logstash pipeline configuration.  
I'm trying to use syslog output plugin so that I can dynamically change the destination syslog server port. I'm trying do tcp/udp connection to different syslog server based on the source of event.

Do this I'm trying to assign syslog output plugin port from @metadata field, initialized earlier in the logstash pipeline per event source type (see below error).

I'm been trying to use

- convert to integer mutate filter
- using event field instead of @metadata field

When I'm assigning port variable from environment variable ${syslogport} it does work, but problem is that I cannot dynamically change the parameter value in the pipeline

I can use other @metadata field without problems (when the type is string)

Problem I'm facing is that plugin doesn't accept parameter because it's not number type.

[ERROR] 2023-01-10 22:59:48.959 [Converge PipelineAction::Create] syslog - Invalid setting for syslog output plugin:

```auto
  output {
    syslog {
      # This setting must be a number
      # Expected number, got "%[@metadata][syslogport]" (type %[@metadata][syslogport])
      port => "%[@metadata][syslogport]"
      ...
    }
  }

```

Thanks for the support

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 11, 2023, 12:24pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-number-type-input-parametrization/322905/2 "2023-01-11T12:24:35Z")

</div>

It seems it's not possible even you do conversion `[@metadata][syslogport]` to integer or `port => "%{[@metadata][syslogport]}"`. The settings: `port=>"3456"` as string is working.

How many ports do you have? If is a few of them you can use IFs and hardcoded port numbs.

---

<div class="post-metadata">

**Author:** ![arirajamaki](https://avatars.discourse-cdn.com/v4/letter/a/a88e57/32.png) [@arirajamaki](https://discuss.elastic.co/u/arirajamaki)\
**Post date:** [January 11, 2023, 12:32pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-number-type-input-parametrization/322905/3 "2023-01-11T12:32:29Z")

</div>

Thanks Rios for reply,

I have only two destination ports, so yes IF condition and hardcoding via environment variables is an option for me

I just wanted to check that Am I missing some basics of logstash pipeline configuration possibilities.

I did try to use event field like [syslogport] with and without convertion to integer (same result)

---

<div class="post-metadata">

**Author:** ![Rios](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/rios/32/95745_2.png) [@Rios](https://discuss.elastic.co/u/Rios)\
**Post date:** [January 11, 2023, 12:38pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-number-type-input-parametrization/322905/4 "2023-01-11T12:38:49Z")

</div>

No need for an ENV variable, try this:

```auto
if [@metadata][syslogport]== "111"
{
    syslog {
      port => 111
      host => "192.168.1.1"
    }
}
else if [@metadata][syslogport]== "222"
{
    syslog {
      port => 222
      host => "192.168.1.2"
    }
}

```

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2023, 12:39pm UTC](https://discuss.elastic.co/t/syslog-output-plugin-number-type-input-parametrization/322905/5 "2023-02-08T12:39:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
