# Using Logstash to modify syslog messages prior to send them to a syslog server

**URL:** <https://discuss.elastic.co/t/using-logstash-to-modify-syslog-messages-prior-to-send-them-to-a-syslog-server/90144>\
**Category:** Logstash\
**Created:** [June 20, 2017, 6:34pm UTC](https://discuss.elastic.co/t/using-logstash-to-modify-syslog-messages-prior-to-send-them-to-a-syslog-server/90144 "2017-06-20T18:34:42Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![leoreginin](https://avatars.discourse-cdn.com/v4/letter/l/ac91a4/32.png) [@leoreginin](https://discuss.elastic.co/u/leoreginin)\
**Post date:** [June 20, 2017, 6:34pm UTC](https://discuss.elastic.co/t/using-logstash-to-modify-syslog-messages-prior-to-send-them-to-a-syslog-server/90144/1 "2017-06-20T18:34:42Z")

</div>

Hi,

Maybe this's a silly question, but I need to remove some part of a syslog message prior to send it to the proper syslog server. Is it possible use Logstash to do that ? How would be the config to, for example, remove an IP Address from the message, keeping the remain message, with the original timestamp, hostname, facility and severity ?

Thanks in advance.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 18, 2017, 6:34pm UTC](https://discuss.elastic.co/t/using-logstash-to-modify-syslog-messages-prior-to-send-them-to-a-syslog-server/90144/2 "2017-07-18T18:34:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
