# Syslog with logstash mapping

**URL:** <https://discuss.elastic.co/t/syslog-with-logstash-mapping/95516>\
**Category:** Elasticsearch\
**Created:** [August 2, 2017, 12:14pm UTC](https://discuss.elastic.co/t/syslog-with-logstash-mapping/95516 "2017-08-02T12:14:45Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![talial](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@talial](https://discuss.elastic.co/u/talial)\
**Post date:** [August 2, 2017, 12:14pm UTC](https://discuss.elastic.co/t/syslog-with-logstash-mapping/95516/1 "2017-08-02T12:14:45Z")

</div>

Hi  
I have logstash that get the syslog from other machines.  
The conf.d file is like:

```
input {
  tcp {
    port => 514
    type => syslog
  }
  udp {
    port => 514
    type => syslog
  }
}

filter {
  if [type] == "syslog" {
    grok {
      match => { "message" => "%{SYSLOGTIMESTAMP:syslog_timestamp} %{SYSLOGHOST:syslog_hostname} %{DATA:syslog_program}(?:\[%{POSINT:syslog_pid}\])?: %{GREEDYDATA:syslog_message}" }
      add_field => ["received_at", "%{@timestamp}"]
      add_field => ["received_from", "%{host}"]
    }
    date {
      match => ["syslog_timestamp", "MMM d HH:mm:ss", "MMM dd HH:mm:ss"]
    }
  }
}

output {
  elasticsearch { hosts => [":9200"] }
}

```

I want to use the feild message with terms in Visualize but there is no feild message to select.  
I have read that this happen when the feild message is not having "keyword" so it can't be used to be aggregatable.  
Is this the reall reason?

How can I add for the message feild:  
"fields": {  
"keyword": {  
"type": "keyword"  
}  
}  
Do I have to change the mapping? and how can I do so?

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 4, 2017, 7:37am UTC](https://discuss.elastic.co/t/syslog-with-logstash-mapping/95516/2 "2017-08-04T07:37:33Z")

</div>

Hey,

you should not aggregate on the `message` field itself, because each field will be different (because almost every message already has a different timestamp). You should aggregate on the extract fields like host, program etc. This is also the reason why the message field does not support this and logstash configures the mapping the way it does.

Maybe you can talk about your use-case and why you want to aggregate so people can find another solution to your problem.

--Alex

---

<div class="post-metadata">

**Author:** ![talial](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@talial](https://discuss.elastic.co/u/talial)\
**Post date:** [August 6, 2017, 10:37am UTC](https://discuss.elastic.co/t/syslog-with-logstash-mapping/95516/3 "2017-08-06T10:37:16Z")

</div>

> [@spinscale](#):
>
> Maybe you can talk about your use-case and why you want to aggregate so people can find another solution to your problem.

Thanks  
I want to create visualization like pie that will show top 5 hosts and number for events on each of this top 5 hosts  
something like this:  
 ![logstash](https://us1.discourse-cdn.com/elastic/original/3X/2/6/26df817345988e7a490c46c73bacf3f02b990423.png)

---

<div class="post-metadata">

**Author:** ![spinscale](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/spinscale/32/25011_2.png) [@spinscale](https://discuss.elastic.co/u/spinscale)\
**Post date:** [August 6, 2017, 8:55pm UTC](https://discuss.elastic.co/t/syslog-with-logstash-mapping/95516/4 "2017-08-06T20:55:52Z")

</div>

then you dont need to aggregate on the `message` field but on the `host` field.

---

<div class="post-metadata">

**Author:** ![talial](https://avatars.discourse-cdn.com/v4/letter/t/3be4f8/32.png) [@talial](https://discuss.elastic.co/u/talial)\
**Post date:** [August 7, 2017, 12:57pm UTC](https://discuss.elastic.co/t/syslog-with-logstash-mapping/95516/5 "2017-08-07T12:57:09Z")

</div>

OK  
Thanks

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 4, 2017, 12:57pm UTC](https://discuss.elastic.co/t/syslog-with-logstash-mapping/95516/6 "2017-09-04T12:57:18Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
