# Using rsyslog server & reporting agent name

**URL:** <https://discuss.elastic.co/t/using-rsyslog-server-reporting-agent-name/281270>\
**Category:** Kibana\
**Created:** [August 12, 2021, 10:07pm UTC](https://discuss.elastic.co/t/using-rsyslog-server-reporting-agent-name/281270 "2021-08-12T22:07:00Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![droidus](https://avatars.discourse-cdn.com/v4/letter/d/13edae/32.png) [@droidus](https://discuss.elastic.co/u/droidus)\
**Post date:** [August 12, 2021, 10:07pm UTC](https://discuss.elastic.co/t/using-rsyslog-server-reporting-agent-name/281270/1 "2021-08-12T22:07:00Z")

</div>

I am using a rsyslog server. I have several of my machines forwardring their logs there, then elastic picks them up. I am going through one of the records, and notice that the hostname is rsyslog, but then when I look in the message, I know it is not a log of rsyslog, but from one of the clients it receives from. Also, the log file path has an indicator that this log is not of the rsyslog server, but again, from one of its clients. What is the best way to sort and organize this data?

---

<div class="post-metadata">

**Author:** ![robertknutzen](https://avatars.discourse-cdn.com/v4/letter/r/f04885/32.png) [@robertknutzen](https://discuss.elastic.co/u/robertknutzen)\
**Post date:** [August 12, 2021, 10:34pm UTC](https://discuss.elastic.co/t/using-rsyslog-server-reporting-agent-name/281270/2 "2021-08-12T22:34:44Z")

</div>

Are you looking at the "host" field that logstash adds to the data? Because by default it seems to be the hostname of the machine it is running on.

if you want to actually get the hostname from the log itself you will need to grok it.

This site is super handy for building a grok expression  
[https://grokconstructor.appspot.com/do/construction](https://grokconstructor.appspot.com/do/construction)

%{SYSLOGBASE} is probably what you'd start with

Another thing you might want to consider is splitting on the rsyslog server, writing different sources to different files so you can differentiate them by the path field.

This won't make your hostname show up right, but its handy for troubleshooting in my experience

Heres a quick dirty example i've used in the past. You'd put it (or probably something similar I make no claims for this things quality I copied and pasted it out of an old machine I have laying around) into your /etc/rsyslog.d/

```auto
$template REMOTESPLIT,"/var/log/remote/%fromhost-ip%/syslog.log"

if $fromhost-ip != '127.0.0.1' then ?REMOTESPLIT
& ~

```

That would split them up by ip and put each machines logs into its own folder.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [September 9, 2021, 10:34pm UTC](https://discuss.elastic.co/t/using-rsyslog-server-reporting-agent-name/281270/3 "2021-09-09T22:34:49Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
