# Syslog pri not working as expected

**URL:** <https://discuss.elastic.co/t/syslog-pri-not-working-as-expected/141902>\
**Category:** Logstash\
**Created:** [July 27, 2018, 8:06am UTC](https://discuss.elastic.co/t/syslog-pri-not-working-as-expected/141902 "2018-07-27T08:06:02Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![sreejiths](https://avatars.discourse-cdn.com/v4/letter/s/4491bb/32.png) [@sreejiths](https://discuss.elastic.co/u/sreejiths)\
**Post date:** [July 27, 2018, 8:06am UTC](https://discuss.elastic.co/t/syslog-pri-not-working-as-expected/141902/1 "2018-07-27T08:06:02Z")

</div>

We have ELK stack running on V5.6.8 for syslog analytics from Network devices ..We used syslog pri filter (give below . Section 1)on the grok to determine the severity levels of the syslogs .. I use syslog\_severity field provided by syslog pri to created a field syslog\_sev\_level which i overwrite based on our organisation requirement ..(give below . Section 2) . But now is see the severity levels is not working a expected ..is it right to use syslog\_severity OR must i use severity\_level ..to get my severity level field syslog\_sev\_level ?? Please advise ..Json output of groked message is provided in Section 3

## Section 1

filter {

```
         if [type] == "syslog" 
            {
                          syslog_pri {}

```

## ##omitted rest of grok Section 2

if [syslog\_severity] == "emergency"  
{  
mutate { add\_field =\> { "syslog\_sev\_level" =\> 0 } }  
}  
else if [syslog\_severity] == "alert"  
{  
mutate { add\_field =\> { "syslog\_sev\_level" =\> 1 } }  
}  
else if [syslog\_severity] == "critical"  
{  
mutate { add\_field =\> { "syslog\_sev\_level" =\> 2 } }  
}  
else if [syslog\_severity] == "error"  
{  
mutate { add\_field =\> { "syslog\_sev\_level" =\> 3 } }  
}  
else if [syslog\_severity] == "warning"  
{  
mutate { add\_field =\> { "syslog\_sev\_level" =\> 4 } }  
}  
else if [syslog\_severity] == "notice"  
{  
mutate { add\_field =\> { "syslog\_sev\_level" =\> 5 } }  
}  
else if [syslog\_severity] == "informational"  
{  
mutate { add\_field =\> { "syslog\_sev\_level" =\> 6 } }  
}  
else if [syslog\_severity] == "debug"  
{  
mutate { add\_field =\> { "syslog\_sev\_level" =\> 7 } }  
}

## Section 3

{  
"\_index": "log-2018.07.26",  
"\_type": "syslog",  
"\_id": "AWTWcRuhV2CegLK-LbhZ",  
"\_version": 1,  
"\_score": null,  
"\_source": {  
**"syslog\_sev\_level": "5",**  
"log\_sequence": "187",  
"syslog\_severity\_code": 5,  
"syslog\_facility": "user-level",  
"syslog\_facility\_code": 1,  
"message": "\<187\>187: Jul 26 19:54:53.220: %C4K\_REDUNDANCY-3-COMMUNICATION: Communication with the peer Supervisor has been established",  
"type": "syslog",  
**"severity\_level": "3",**  
**"syslog\_severity": "notice",**  
"tags": [  
"cisco"  
],  
"host\_group": "BUILDING",  
"hostname": "lgsdtccss02",  
"@timestamp": "2018-07-26T11:54:54.227Z",  
"log\_date": "Jul 26 19:54:53.220",  
"host": "12.1.1.1",  
"log\_message": "Communication with the peer Supervisor has been established",  
"Access\_switch": "Yes",  
"facility": "C4K\_REDUNDANCY",  
"facility\_mnemonic": "COMMUNICATION",  
"Critical\_device": "No"  
},  
"fields": {  
"@timestamp": [  
1532606094227  
]  
},  
"highlight": {  
"host": [  
"@kibana-highlighted-field@10.95.255.11@/kibana-highlighted-field@"  
]  
},  
"sort": [  
1532606094227  
]  
}

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 24, 2018, 8:06am UTC](https://discuss.elastic.co/t/syslog-pri-not-working-as-expected/141902/2 "2018-08-24T08:06:06Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
