# Wrong indexes with syslog

**URL:** <https://discuss.elastic.co/t/wrong-indexes-with-syslog/176899>\
**Category:** Logstash\
**Created:** [April 15, 2019, 11:56am UTC](https://discuss.elastic.co/t/wrong-indexes-with-syslog/176899 "2019-04-15T11:56:10Z")\
**Posts on this page:** 9\
**Page:** 1

<div class="post-metadata">

**Author:** ![Farhad\_Kocharli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farhad_kocharli/32/43852_2.png) [@Farhad\_Kocharli](https://discuss.elastic.co/u/Farhad_Kocharli)\
**Post date:** [April 15, 2019, 11:56am UTC](https://discuss.elastic.co/t/wrong-indexes-with-syslog/176899/1 "2019-04-15T11:56:10Z")

</div>

I have configured Logstash (see below configuration) to get logs from Cisco devices with syslog. Despite I have configured in "output" section index (index =\> "network-%{+YYYY.MM.dd}") on Kibana side I see wrong index. It shows %{[@metadata][beat]}-%{[@metadata][version]} instead of index ([screenshot attached](https://dropmefiles.com/0VYfG)).

P.S with Winlogbeat and Filebeat everything ok.

Can anybody help to fix this issue?

# 

```
# INPUT - Logstash listens on port 8514 for these logs.
#

input {
  syslog {
    port => "8514"
    type => "syslog"
  }
}

filter {
if [type] == "syslog" {
grok {
patterns_dir => ["/opt/logstash/patterns"]
match => [ 
"message", "%{SYSLOG5424PRI}%{NUMBER:log_sequence#}: %{CISCOTIMESTAMP:log_date}: %%{CISCO_REASON:facility}-%{INT:severity_level}-%{CISCO_REASON:facility_mnemonic}: %{GREEDYDATA:message}", 
"message", "%{SYSLOG5424PRI}%{NUMBER:log_sequence#}: %{CISCOTIMESTAMP:log_date}: %%{CISCO_REASON:facility}-%{CISCO_REASON:facility_sub}-%{INT:severity_level}-%{CISCO_REASON:facility_mnemonic}: %{GREEDYDATA:message}" 
]
overwrite => ["message"]
remove_field => ["syslog5424_pri", "@version"]
}
mutate {
gsub => [
"severity_level", "0", "0 - Emergency",
"severity_level", "1", "1 - Alert",
"severity_level", "2", "2 - Critical",
"severity_level", "3", "3 - Error",
"severity_level", "4", "4 - Warning",
"severity_level", "5", "5 - Notification",
"severity_level", "6", "6 - Informational"
]
}
}
}
}

output {
  # Something went wrong with the grok parsing, don't discard the messages though
  if "_grokparsefailure" in [tags] {
    file {
      path => "/tmp/fail-%{type}-%{+YYYY.MM.dd}.log"
    }
  }

  # The message was parsed correctly, and should be sent to elasicsearch.
  if "cisco" in [tags] {
    #file {
    # path => "/tmp/%{type}-%{+YYYY.MM.dd}.log"
    #}

    elasticsearch {
      hosts => "localhost:9200"
      manage_template => false
      index => "network-%{+YYYY.MM.dd}"
# document_id => "%{fingerprint}"
    }
  }
}
```

---

<div class="post-metadata">

**Author:** ![Farhad\_Kocharli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farhad_kocharli/32/43852_2.png) [@Farhad\_Kocharli](https://discuss.elastic.co/u/Farhad_Kocharli)\
**Post date:** [April 16, 2019, 7:11am UTC](https://discuss.elastic.co/t/wrong-indexes-with-syslog/176899/2 "2019-04-16T07:11:40Z")

</div>

When I delete "filter" section I can see "network-\*" index on Kibana. But it shows logs from winlogbeat. Any ideas?

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 16, 2019, 12:26pm UTC](https://discuss.elastic.co/t/wrong-indexes-with-syslog/176899/3 "2019-04-16T12:26:53Z")

</div>

Do you have multiple configuration files in path.config?

---

<div class="post-metadata">

**Author:** ![Farhad\_Kocharli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farhad_kocharli/32/43852_2.png) [@Farhad\_Kocharli](https://discuss.elastic.co/u/Farhad_Kocharli)\
**Post date:** [April 16, 2019, 12:39pm UTC](https://discuss.elastic.co/t/wrong-indexes-with-syslog/176899/4 "2019-04-16T12:39:22Z")

</div>

Yes I have 3 files there (/etc/logstash/conf.d).

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 16, 2019, 12:58pm UTC](https://discuss.elastic.co/t/wrong-indexes-with-syslog/176899/5 "2019-04-16T12:58:43Z")

</div>

> [@Farhad\_Kocharli](#):
>
> Yes I have 3 files there (/etc/logstash/conf.d)

OK. Those three files are combined into one configuration. Events are read from all of the inputs, sent through all of the filters, and, unless there are conditionals, sent to all of the outputs.

If you want each configuration to be standalone you would have to configure them as [pipelines](https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html).

---

<div class="post-metadata">

**Author:** ![Farhad\_Kocharli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farhad_kocharli/32/43852_2.png) [@Farhad\_Kocharli](https://discuss.elastic.co/u/Farhad_Kocharli)\
**Post date:** [April 16, 2019, 1:43pm UTC](https://discuss.elastic.co/t/wrong-indexes-with-syslog/176899/6 "2019-04-16T13:43:28Z")

</div>

I did it like this but it also does not help. Any other ideas?

```
# This file is where you define your pipelines. You can define multiple.
# For more information on multiple pipelines, see the documentation:
# https://www.elastic.co/guide/en/logstash/current/multiple-pipelines.html

- pipeline.id: main
  path.config: "/etc/logstash/conf.d/*.conf"

- pipeline.id: cisco
  path.config: "/etc/logstash/conf.d/cisco.conf"

- pipeline.id: vmware
  path.config: "/etc/logstash/conf.d/vmware.conf"

- pipeline.id: windows
  path.config: "/etc/logstash/conf.d/windows.conf"
```

---

<div class="post-metadata">

**Author:** ![Badger](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/badger/32/25190_2.png) [@Badger](https://discuss.elastic.co/u/Badger)\
**Post date:** [April 16, 2019, 1:52pm UTC](https://discuss.elastic.co/t/wrong-indexes-with-syslog/176899/7 "2019-04-16T13:52:12Z")

</div>

> [@Farhad\_Kocharli](#):
>
> ```
> - pipeline.id: main
> path.config: "/etc/logstash/conf.d/*.conf"
> 
> ```

That is telling it to combine all three files and run them as a single pipeline. Remove those two lines.

---

<div class="post-metadata">

**Author:** ![Farhad\_Kocharli](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/farhad_kocharli/32/43852_2.png) [@Farhad\_Kocharli](https://discuss.elastic.co/u/Farhad_Kocharli)\
**Post date:** [April 17, 2019, 5:08am UTC](https://discuss.elastic.co/t/wrong-indexes-with-syslog/176899/8 "2019-04-17T05:08:16Z")

</div>

Thanks a lot. It works now.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [May 15, 2019, 5:08am UTC](https://discuss.elastic.co/t/wrong-indexes-with-syslog/176899/9 "2019-05-15T05:08:21Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
