Transfer Unix messages to ELS


(Solomon) #1

Hello all,
I need your help to understand how I forward UNIX SYSTEM (SOLARIS) messages to ELS?

Thanks


(Magnus Bäck) #2

Are you talking about syslog messages? And ELS means Elasticsearch?

https://www.elastic.co/guide/en/logstash/current/config-examples.html should give you some inspiration. The syslog example there sets up network listeners but if you're running Logstash on the Solaris host you could read from local files instead with a file input plugin.


(Solomon) #3

Does that mean I need to install Logstash + Plugin syslog on each UNIX server?


(Magnus Bäck) #4

No. You can configure the local syslog daemon to ship the messages over the network. Another option is to install Filebeat to ship the logs from disk.

There are many ways of doing this. The sooner you tell us what particular requirements you quicker things go.


(Solomon) #5

Does LOGSTASH know to accept syslog events?


(Magnus Bäck) #6

The link I posted contains an example of just that.


(Solomon) #7

Thank you,


(system) #8

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.