# What is the best approach to capture Linux(Ubuntu) server logs?

**URL:** <https://discuss.elastic.co/t/what-is-the-best-approach-to-capture-linux-ubuntu-server-logs/93415>\
**Category:** Logstash\
**Created:** [July 17, 2017, 3:14pm UTC](https://discuss.elastic.co/t/what-is-the-best-approach-to-capture-linux-ubuntu-server-logs/93415 "2017-07-17T15:14:28Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [July 17, 2017, 3:14pm UTC](https://discuss.elastic.co/t/what-is-the-best-approach-to-capture-linux-ubuntu-server-logs/93415/1 "2017-07-17T15:14:28Z")

</div>

Can someone suggest me the best way to capture Ubuntu server logs and send it to Elasticsearch? I am trying to use Logstash but on top of that is there any other plugin? For windows event logs Winlogbeat and Logstash can be used. Like wise for Linux server logs, is there any other tool to use along with Logstash?  
Thanks in advance.

---

<div class="post-metadata">

**Author:** ![Makra](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@Makra](https://discuss.elastic.co/u/Makra)\
**Post date:** [July 17, 2017, 6:11pm UTC](https://discuss.elastic.co/t/what-is-the-best-approach-to-capture-linux-ubuntu-server-logs/93415/2 "2017-07-17T18:11:37Z")

</div>

You can use syslog-ng along with logstash.

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [July 17, 2017, 7:31pm UTC](https://discuss.elastic.co/t/what-is-the-best-approach-to-capture-linux-ubuntu-server-logs/93415/3 "2017-07-17T19:31:44Z")

</div>

Hi Makra, can you please say what disadvantages I will have if I use Logstash alone?

---

<div class="post-metadata">

**Author:** ![Makra](https://avatars.discourse-cdn.com/v4/letter/m/8491ac/32.png) [@Makra](https://discuss.elastic.co/u/Makra)\
**Post date:** [July 18, 2017, 6:38am UTC](https://discuss.elastic.co/t/what-is-the-best-approach-to-capture-linux-ubuntu-server-logs/93415/4 "2017-07-18T06:38:00Z")

</div>

Depends on the requirement. If you have already syslog-ng server is running then you can use it to forward log to logstash. You can also convert log format ( e.g to JSON ) on the fly in syslog-ng itself. But this comes at the cost of one extra read/write operations. Rather you can use, filebeat/Winlogbeat to forward the same logs from the source. So basically, syslog-ng is used to collect logs from various sources in a centralized location and then forwards/distribute the logs to logstash for further refinement/processing which in turn may forward logs to ES-\>Kibana.

In general

`Logs from n sources -> Syslog-ng Server -> Logstash -> ES -> Kibana`

**OR**

```
logs from source 1 -> Logstash -> ES -> Kibana

logs from source 2 -> Logstash -> ES -> Kibana

logs from source 3 -> Logstash -> ES -> Kibana

...............................................
...............................................

logs from source n -> Logstash -> ES -> Kibana

```

Now you have to find it out, which one best suits your requirement.

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [July 18, 2017, 2:54pm UTC](https://discuss.elastic.co/t/what-is-the-best-approach-to-capture-linux-ubuntu-server-logs/93415/5 "2017-07-18T14:54:41Z")

</div>

Thanks for the detailed information Makra. Right now, we don't have Syslog-ng server running. So I will go with "Logs from n sources -\> Syslog-ng Server -\> Logstash -\> ES -\> Kibana". But will there be any overhead(CPU,Memory) on the server if I use only Logstash?

---

<div class="post-metadata">

**Author:** ![amruth](https://avatars.discourse-cdn.com/v4/letter/a/43a26b/32.png) [@amruth](https://discuss.elastic.co/u/amruth)\
**Post date:** [July 20, 2017, 6:33pm UTC](https://discuss.elastic.co/t/what-is-the-best-approach-to-capture-linux-ubuntu-server-logs/93415/6 "2017-07-20T18:33:39Z")

</div>

Any update on this please...

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [August 17, 2017, 6:33pm UTC](https://discuss.elastic.co/t/what-is-the-best-approach-to-capture-linux-ubuntu-server-logs/93415/7 "2017-08-17T18:33:44Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
