# TCP/UDP VS syslog

**URL:** <https://discuss.elastic.co/t/tcp-udp-vs-syslog/322927>\
**Category:** Logstash\
**Created:** [January 11, 2023, 1:01pm UTC](https://discuss.elastic.co/t/tcp-udp-vs-syslog/322927 "2023-01-11T13:01:13Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![m3bgwad](https://avatars.discourse-cdn.com/v4/letter/m/a183cd/32.png) [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Post date:** [January 11, 2023, 1:01pm UTC](https://discuss.elastic.co/t/tcp-udp-vs-syslog/322927/1 "2023-01-11T13:01:13Z")

</div>

What is differences between the below.

```auto
input {
  tcp {
    port => 514
    type => syslog
  }
  udp {
    port => 514
    type => syslog
  }
}

```

VS

```auto
input {
  syslog {
    port => 514
 }
}

```

If I need to receive syslog messages and use "TLS" Encryption. In Syslog input plugin doesn't supported so far, I try to find the alternative solution, if there is please help me and thank you.

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 11, 2023, 1:06pm UTC](https://discuss.elastic.co/t/tcp-udp-vs-syslog/322927/2 "2023-01-11T13:06:27Z")

</div>

The `syslog` input expects messages to follow the syslog format defined in `RFC3164` and will automatically parse the message if the format is correct.

The `tcp` or `udp` input will receive any kind of message, but you will need to build your own parse for it.

Since you need to use TLS, you can do that using the `tcp` input.

---

<div class="post-metadata">

**Author:** ![m3bgwad](https://avatars.discourse-cdn.com/v4/letter/m/a183cd/32.png) [@m3bgwad](https://discuss.elastic.co/u/m3bgwad)\
**Post date:** [January 11, 2023, 1:21pm UTC](https://discuss.elastic.co/t/tcp-udp-vs-syslog/322927/3 "2023-01-11T13:21:41Z")

</div>

> [@leandrojmp](#):
>
> The `tcp` or `udp` input will receive any kind of message, but you will need to build your own parse for it.

Please Explain more on this line  
whet you mean?

> [@leandrojmp](#):
>
> own parse for it.

I thank you mean use the grok message to handle the syslog message .

---

<div class="post-metadata">

**Author:** ![leandrojmp](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/leandrojmp/32/107231_2.png) [@leandrojmp](https://discuss.elastic.co/u/leandrojmp)\
**Post date:** [January 11, 2023, 1:31pm UTC](https://discuss.elastic.co/t/tcp-udp-vs-syslog/322927/4 "2023-01-11T13:31:40Z")

</div>

> [@m3bgwad](#):
>
> Please Explain more on this line

I'm not sure there is anything else to explain, the `tcp` and `udp` input will receive any message will send, they do not expect the message to follow any format, the `syslog` input expects the message to follow a specfic format.

> [@m3bgwad](#):
>
> I thank you mean use the grok message to handle the syslog message .

You can use grok, dissect, kv, json, it depends on the format your message, but you need to use any parsing filter that logstash have to parse the message.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [February 8, 2023, 1:32pm UTC](https://discuss.elastic.co/t/tcp-udp-vs-syslog/322927/5 "2023-02-08T13:32:37Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
