# Where would my syslogs be?

**URL:** https://discuss.elastic.co/t/where-would-my-syslogs-be/288819
**Category:** Logstash
**Created:** [November 9, 2021, 8:19pm UTC](https://discuss.elastic.co/t/where-would-my-syslogs-be/288819 "2021-11-09T20:19:28Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![MKirby](https://avatars.discourse-cdn.com/v4/letter/m/e56c9b/32.png) [@MKirby](https://discuss.elastic.co/u/MKirby)
#### Post date: [November 9, 2021, 8:19pm UTC](https://discuss.elastic.co/t/where-would-my-syslogs-be/288819/1 "2021-11-09T20:19:28Z")

</div>

Good Afternoon Elastic team. I have proof via packetbeat that my syslogs are flowing to my Logstash server. I can also netstat and confirm the ports are open and listening on the configured port. I have the following configured in my logstash.conf, inidicating what i want to have happen with my syslogs.

```auto
output {
     elasticsearch {
          hosts => ["ES_IP_ADD:9200"]
          user => "ES_username"
          password => "ES_user_pass"
     }
   stdout { codec => rubydebug }
}

```

When I run either a Trace or a Debug on my logstash I see the following:

````auto
[2021-11-09T14:36:22,761][INFO][logstash.agent] Pipelines running {:count=>1, :running_pipelines=>[:main], :non_running_pipelines=>[]}
14:36:22.395
logstash.log
[logstash.log][DEBUG] Compiled output P[output-elasticsearch{"hosts"=>["http://10.12.36.52:9200"], "index"=>"%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}", "user"=>"ES_Username", "password"=>"ES_User_pass"}|[file]/etc/logstash/conf.d/logstash-sample.conf:22:3:``` elasticsearch { hosts => ["http://1ES_IP_Add:9200"] index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}" user => "ES_Username" password => "ES_User_password" } ```] into org.logstash.config.ir.compiler.ComputeStepSyntaxElement@3fdc2b9c
14:36:22.395
logstash.log
[logstash.log][DEBUG] Compiled output P[output-elasticsearch{"hosts"=>["http://ES_IP_Add:9200"], "index"=>"%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}", "user"=>"ES_Username", "password"=>"ES_User_pass"}|[file]/etc/logstash/conf.d/logstash-sample.conf:22:3:``` elasticsearch { hosts => ["http://10.12.36.52:9200"] index => "%{[@metadata][beat]}-%{[@metadata][version]}-%{+YYYY.MM.dd}" user => "elastic" password => "m@rc0n12021" } ```] into org.logstash.config.ir.compiler.ComputeStepSyntaxElement@3fdc2b9c

````

When I run: http://ES\_IP\_ADD:9200/\_cat/indices?v on my windows server I do not see anything that would indicate an inidex that would house my information.

If anyone can help with this it would be greatly appreciated. Thank you.

---

<div class="post-metadata">

### Author: ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)
#### Post date: [December 7, 2021, 8:20pm UTC](https://discuss.elastic.co/t/where-would-my-syslogs-be/288819/2 "2021-12-07T20:20:04Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
