# Syslog\_severity field is always using the default notice rather than the actual severity

**URL:** <https://discuss.elastic.co/t/syslog-severity-field-is-always-using-the-default-notice-rather-than-the-actual-severity/212478>\
**Category:** Logstash\
**Created:** [December 19, 2019, 11:53am UTC](https://discuss.elastic.co/t/syslog-severity-field-is-always-using-the-default-notice-rather-than-the-actual-severity/212478 "2019-12-19T11:53:52Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![oldhamuk](https://avatars.discourse-cdn.com/v4/letter/o/97f17d/32.png) [@oldhamuk](https://discuss.elastic.co/u/oldhamuk)\
**Post date:** [December 19, 2019, 11:53am UTC](https://discuss.elastic.co/t/syslog-severity-field-is-always-using-the-default-notice-rather-than-the-actual-severity/212478/1 "2019-12-19T11:53:52Z")

</div>

Good Morning,

I'm fairly new to ELK but have managed to build my self solution I can use for a syslog server and I'm happy with it with the exceptions of one thing at the moment. The severity of the syslog events seems to always be defaulting to the default of notice. Now I believe there is sometimes issues relating to the RFC and how different vendors format the messages so I'm not sure if this is what is causing it.

My setup consists of a Logstash Server, Elastic Cluster and a Kibana Server all hosted on separate boxes.

My logstash config from /etc/logstash/conf.d/syslog.conf :

input {  
tcp {  
port =\> 514  
type =\> syslog  
}  
udp {  
port =\> 514  
type =\> syslog  
}  
}  
filter {  
syslog\_pri { }  
}  
output {  
elasticsearch { hosts =\> ["10.x.x.x:9200"]  
index =\> "loghive-hdc-%{+YYYY.MM.dd}" }  
}

How the event looks when its being stored in the Elastic Cluster:

 ![Screenshot 2019-12-19 at 11.44.22](https://us1.discourse-cdn.com/elastic/original/3X/a/f/af94cef17c85fa92e8a1fb598f3a3d928fc0834a.png)

 ![Screenshot 2019-12-19 at 11.44.35](https://us1.discourse-cdn.com/elastic/original/3X/f/5/f5d9de115344feb0f07d0c166d4e2c00cd747eee.png)

The correct severity is being sent by the device and the existing syslog server is storing that fine:

 ![Screenshot 2019-12-19 at 11.46.46](https://us1.discourse-cdn.com/elastic/original/3X/5/1/51ffac523f3cdc4ce625415fc543d7aeba1f1935.png)

If anybody can help me I'd be very grateful. Again I'm new to ELK so apologies in advance if I'm missing something obvious.

Mark

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [December 19, 2019, 4:12pm UTC](https://discuss.elastic.co/t/syslog-severity-field-is-always-using-the-default-notice-rather-than-the-actual-severity/212478/2 "2019-12-19T16:12:07Z")

</div>

The syslog\_pri filter parses the severity and priority from a field on the event. By default it looks for a field called syslog\_pri, and if that is missing it uses user-level/notice (13).

You need to use dissect (or grok) to extract the PRI from [message] into [syslog\_pri].

---

<div class="post-metadata">

**Author:** ![oldhamuk](https://avatars.discourse-cdn.com/v4/letter/o/97f17d/32.png) [@oldhamuk](https://discuss.elastic.co/u/oldhamuk)\
**Post date:** [December 20, 2019, 8:36am UTC](https://discuss.elastic.co/t/syslog-severity-field-is-always-using-the-default-notice-rather-than-the-actual-severity/212478/3 "2019-12-20T08:36:52Z")

</div>

Ok thank you, I'll read into dissect and gork see how I get on.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [January 17, 2020, 8:37am UTC](https://discuss.elastic.co/t/syslog-severity-field-is-always-using-the-default-notice-rather-than-the-actual-severity/212478/4 "2020-01-17T08:37:07Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
