# Syslog to Linux

**URL:** <https://discuss.elastic.co/t/syslog-to-linux/141211>\
**Category:** Elasticsearch\
**Created:** [July 23, 2018, 3:42pm UTC](https://discuss.elastic.co/t/syslog-to-linux/141211 "2018-07-23T15:42:15Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![Marcos\_Felix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_felix/32/32486_2.png) [@Marcos\_Felix](https://discuss.elastic.co/u/Marcos_Felix)\
**Post date:** [July 23, 2018, 3:42pm UTC](https://discuss.elastic.co/t/syslog-to-linux/141211/1 "2018-07-23T15:42:15Z")

</div>

Hello,  
I don't know if I am on the right section but here it goes:  
I have a syslog server and I already connected for it to send the logs to my linux box where I have ELK installed. I have the IP and everything but I am not very knowledgeable on this. So, I don't know how to check if it actually is sending syslog to the Linux box or not and also where would this log go (definitely /var/log right?)

Could anyone help?

---

<div class="post-metadata">

**Author:** ![Marcos\_Felix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_felix/32/32486_2.png) [@Marcos\_Felix](https://discuss.elastic.co/u/Marcos_Felix)\
**Post date:** [July 24, 2018, 9:09am UTC](https://discuss.elastic.co/t/syslog-to-linux/141211/2 "2018-07-24T09:09:23Z")

</div>

I have already configured fortigate syslogs to be sent to Linux, anyone know how to get these syslogs and upload to elasticsearch/kibana? do I use logstash, logbeat?

---

<div class="post-metadata">

**Author:** ![Charaf\_Ahmed](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/charaf_ahmed/32/30467_2.png) [@Charaf\_Ahmed](https://discuss.elastic.co/u/Charaf_Ahmed)\
**Post date:** [July 24, 2018, 9:55am UTC](https://discuss.elastic.co/t/syslog-to-linux/141211/3 "2018-07-24T09:55:11Z")

</div>

Logstash usage or beats depend on what you want to do, although it's two tools make relatively the same thing with a few difference.

For what you want to do, I think it will fadra first understand the usefulness of each.  
link: [https://www.elastic.co/fr/products/beats](https://www.elastic.co/fr/products/beats)

Beat 1 |  
Beat 2 | ---\> Logstash (optionnal ) --\> ES --\> Kibana  
Beat .. |  
Beat n |

---

<div class="post-metadata">

**Author:** ![Marcos\_Felix](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/marcos_felix/32/32486_2.png) [@Marcos\_Felix](https://discuss.elastic.co/u/Marcos_Felix)\
**Post date:** [July 24, 2018, 10:45am UTC](https://discuss.elastic.co/t/syslog-to-linux/141211/4 "2018-07-24T10:45:03Z")

</div>

> [@Charaf\_Ahmed](#):
>
> For what you want to do, I think it will fadra first understand the usefulness o

Thank for the reply,  
I have the port where the syslogs are being sent to  
If I am using logstash, do I just change the configuration to listen to the port that syslogs are being sent?

```
input {
  tcp {
    port => SYSLOG_PORT
    type => syslog
  }
  udp {
    port => SYSLOG_PORT
    type => syslog
  }
}
    filter {
      if [type] == "syslog" {
        grok {
          match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
          add_field => ["received_at", "%{@timestamp}"]
          add_field => ["received_from", "%{host}"]
        }
        date {
          match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
        }
      }
    }
    output {
      elasticsearch { hosts => ["10.130.233.242:9200"] }
      stdout { codec => rubydebug }
    }

```

Is that all or do I need to do something else?

edit: forgot to add the syslogs are coming from fortigate

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 21, 2018, 10:45am UTC](https://discuss.elastic.co/t/syslog-to-linux/141211/5 "2018-08-21T10:45:11Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
