# \[UNSUPPORTED\] Extract fields from syslog messages

**URL:** <https://discuss.elastic.co/t/unsupported-extract-fields-from-syslog-messages/65402>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [November 8, 2016, 8:27pm UTC](https://discuss.elastic.co/t/unsupported-extract-fields-from-syslog-messages/65402 "2016-11-08T20:27:06Z")\
**Posts on this page:** 6\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andrrrey](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@Andrrrey](https://discuss.elastic.co/u/Andrrrey)\
**Post date:** [November 8, 2016, 8:27pm UTC](https://discuss.elastic.co/t/unsupported-extract-fields-from-syslog-messages/65402/1 "2016-11-08T20:27:06Z")

</div>

There was similar question about JSON messages before...  
Setup:

txt file--------\> filebeat----------\>elasticsearch

File has syslog formatted and not formatted messages from different devices (sometimes format differs a lot )

Questions:

Is it possible to extract additional fields from the "message" field, when message is clear "syslog"?

Is it possible to introduce an additional fields based on conditions (regexp) of having some information in the message?

Documentation on the "processors" is very vague, tried it , no luck.  
Any information would be appreciated.

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 9, 2016, 10:44am UTC](https://discuss.elastic.co/t/unsupported-extract-fields-from-syslog-messages/65402/2 "2016-11-09T10:44:36Z")

</div>

Filebeat currently does not extract any fields from the log messages. It can process json in case your messages are in JSON format. Otherwise please use grok in Logstash or elasticsearch ingest.

---

<div class="post-metadata">

**Author:** ![Andrrrey](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@Andrrrey](https://discuss.elastic.co/u/Andrrrey)\
**Post date:** [November 9, 2016, 3:34pm UTC](https://discuss.elastic.co/t/unsupported-extract-fields-from-syslog-messages/65402/3 "2016-11-09T15:34:30Z")

</div>

Ruflin, thanks for reply.

So the answer on my first question is "Not supported"

What about my second questions?

I would like to analyse message with regular expression and introduce a new filed based on result. I assume it is what processors are for. Can you provide an example?

---

<div class="post-metadata">

**Author:** ![ruflin](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/ruflin/32/3116_2.png) [@ruflin](https://discuss.elastic.co/u/ruflin)\
**Post date:** [November 10, 2016, 9:26am UTC](https://discuss.elastic.co/t/unsupported-extract-fields-from-syslog-messages/65402/4 "2016-11-10T09:26:06Z")

</div>

2 is currently also not possible. The main target of processors in filebeat is to filter out lines which should not be shipped. There are some ideas how we could extend this in the future.

At the moment I strongly recommend to do the above in Logstash.

---

<div class="post-metadata">

**Author:** ![Andrrrey](https://avatars.discourse-cdn.com/v4/letter/a/ba8739/32.png) [@Andrrrey](https://discuss.elastic.co/u/Andrrrey)\
**Post date:** [November 10, 2016, 2:43pm UTC](https://discuss.elastic.co/t/unsupported-extract-fields-from-syslog-messages/65402/5 "2016-11-10T14:43:22Z")

</div>

OK . I got it.  
Thanks for the information

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [December 8, 2016, 2:43pm UTC](https://discuss.elastic.co/t/unsupported-extract-fields-from-syslog-messages/65402/6 "2016-12-08T14:43:33Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
