# Weird test configuration problem || log\_file --\> Syslog-ng --\> Logstash --\> another\_file

**URL:** <https://discuss.elastic.co/t/weird-test-configuration-problem-log-file-syslog-ng-logstash-another-file/270253>\
**Category:** Logstash\
**Created:** [April 15, 2021, 2:39pm UTC](https://discuss.elastic.co/t/weird-test-configuration-problem-log-file-syslog-ng-logstash-another-file/270253 "2021-04-15T14:39:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![stillfreem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stillfreem/32/85628_2.png) [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Post date:** [April 15, 2021, 2:39pm UTC](https://discuss.elastic.co/t/weird-test-configuration-problem-log-file-syslog-ng-logstash-another-file/270253/1 "2021-04-15T14:39:33Z")

</div>

Hi All, please ignore the stupid use case as I only use this config for testing purposes.

I have an Ubuntu server with installed syslog-ng and Logstash.  
I'd like to do the following:

I have a cronjob that on every minute manually add one log FW entry into one file **ubuntu\_in**  
Something like:  
` echo "blablba" >> ubuntu_in`  
I take this file in Syslog-ng as input (using File source driver) and get it on localhost:4444 (using network destination driver)

Logstash listens on localhost:4444 (using input plugin Syslog) and should write these logs to another file on the same Ubuntu server called **ubuntu\_out**

These are my configurations  
SYSLOG-NG

 ![9](https://us1.discourse-cdn.com/elastic/original/3X/e/9/e9e9a95dc90c85eb13602362500cd0672fe8d7d0.png)

LOGSTASH (the file contains artifacts from another test but they are commented and plays no role here)

 ![10](https://us1.discourse-cdn.com/elastic/original/3X/0/d/0d460910bbf0503d18323d7e18be94920b60a53d.png)

Is that scenario even possible?  
I can't see file ubuntu\_out anyway?

Could you please tell me what I do wrong?

I'm placing here just a simple test i did with lsof to see if both tools connect with each other and they seems to have although I am not a network expert.

 ![11](https://us1.discourse-cdn.com/elastic/original/3X/c/e/cee80103877fed38f2903b41998c3f1c8a97bb6e.png)

Thank you in advance.

---

<div class="post-metadata">

**Author:** ![stillfreem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/stillfreem/32/85628_2.png) [@stillfreem](https://discuss.elastic.co/u/stillfreem)\
**Post date:** [April 15, 2021, 6:58pm UTC](https://discuss.elastic.co/t/weird-test-configuration-problem-log-file-syslog-ng-logstash-another-file/270253/2 "2021-04-15T18:58:42Z")

</div>

Got it 🙂  
Just had to add in Logstash in the **FIle output plugin** the parameter **file\_mode =\> \<some\_perm\>** and it worked.  
` output { #elasticsearch { hosts => ["localhost:9200"] } #stdout { codec => rubydebug } file { path => "/home/dimma/testfolder/ubuntu_out" file_mode => 0644 }`

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 13, 2021, 6:59pm UTC](https://discuss.elastic.co/t/weird-test-configuration-problem-log-file-syslog-ng-logstash-another-file/270253/3 "2021-05-13T18:59:24Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
