Send events to a syslog server.
You can send messages compliant with RFC3164 or RFC5424 UDP or TCP syslog transport is supported
output {
syslog {
appname => ... # string (optional), default: "LOGSTASH"
codec => ... # codec (optional), default: "plain"
facility => ... # string, one of ["kernel", "user-level", "mail", "daemon", "security/authorization", "syslogd", "line printer", "network news", "uucp", "clock", "security/authorization", "ftp", "ntp", "log audit", "log alert", "clock", "local0", "local1", "local2", "local3", "local4", "local5", "local6", "local7"] (required)
host => ... # string (required)
msgid => ... # string (optional), default: "-"
port => ... # number (required)
procid => ... # string (optional), default: "-"
protocol => ... # string, one of ["tcp", "udp"] (optional), default: "udp"
rfc => ... # string, one of ["rfc3164", "rfc5424"] (optional), default: "rfc3164"
severity => ... # string, one of ["emergency", "alert", "critical", "error", "warning", "notice", "informational", "debug"] (required)
sourcehost => ... # string (optional), default: "%{host}"
workers => ... # number (optional), default: 1
}
}
application name for syslog message
The codec used for output data. Output codecs are a convenient method for encoding your data before it leaves the output, without needing a separate filter in your Logstash pipeline.
Only handle events without any of these tags. Note this check is additional to type and tags.
facility label for syslog message
syslog server address to connect to
message id for syslog message
syslog server port to connect to
process id for syslog message
syslog server protocol. you can choose between udp and tcp
syslog message format: you can choose between rfc3164 or rfc5424
severity label for syslog message
source host for syslog message
Only handle events with all of these tags. Note that if you specify a type, the event must also match that type. Optional.
timestamp for syslog message
The type to act on. If a type is given, then this output will only act on messages with the same type. See any input plugin’s “type” attribute for more. Optional.
The number of workers to use for this output. Note that this setting may not be useful for all outputs.