# Syslog TCP input normalization

**URL:** <https://community.graylog.org/t/syslog-tcp-input-normalization/23774>\
**Category:** Graylog Central (peer support)\
**Created:** [May 10, 2022, 12:15pm UTC](https://community.graylog.org/t/syslog-tcp-input-normalization/23774 "2022-05-10T12:15:49Z")\
**Posts on this page:** 5\
**Page:** 1

<div class="post-metadata">

**Author:** ![dio99](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dio99/32/3351_2.png) [@dio99](https://community.graylog.org/u/dio99)\
**Post date:** [May 10, 2022, 12:15pm UTC](https://community.graylog.org/t/syslog-tcp-input-normalization/23774/1 "2022-05-10T12:15:49Z")

</div>

running version 4.2x  
i know in past i could disable the normalization of logs on input syslog tcp, i think it was using kv but i cant remember where i could disable or remove that now. due to all fields get in string and i want to use pipeline rules i created for the normalization . mayby not possible now in newer versions of graylog to disable/remove that default parsing? sure i can use raw syslog input for this…

// Anders

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [May 10, 2022, 10:09pm UTC](https://community.graylog.org/t/syslog-tcp-input-normalization/23774/2 "2022-05-10T22:09:32Z")

</div>

Hello @dio99

> [@dio99](#):
>
> i know in past i could disable the normalization of logs on input syslog tcp,

Only thing with the newer version that I see is “Delete” an extractor or pause the INPUT.

It’s not clear to me on what you end goal is, could you explain it in greater detail?

---

<div class="post-metadata">

**Author:** ![dio99](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/dio99/32/3351_2.png) [@dio99](https://community.graylog.org/u/dio99)\
**Post date:** [May 11, 2022, 6:49am UTC](https://community.graylog.org/t/syslog-tcp-input-normalization/23774/3 "2022-05-11T06:49:50Z")

</div>

Hellu i want to use my own rules to normalize the logs that are normalized on the syslog tcp input, by default it parse it and set all fields to string.  
so i want to stop the parsing that is done on the syslog input by default, this not in any extractor since that is empty.

---

<div class="post-metadata">

**Author:** ![gsmith](https://sea2.discourse-cdn.com/flex016/user_avatar/community.graylog.org/gsmith/32/1222_2.png) [@gsmith](https://community.graylog.org/u/gsmith)\
**Post date:** [May 11, 2022, 11:37pm UTC](https://community.graylog.org/t/syslog-tcp-input-normalization/23774/4 "2022-05-11T23:37:55Z")

</div>

Hello,

> [@dio99](#):
>
> i want to use my own rules to normalize the logs that are normalized on the syslog tcp input, by default it parse it and set all fields to string.

I see, if you referring to the default fields such as timestamp, message, etc… then you would need to create a **new index template** and attach it to **new index set**.

Here is a couple ideas depending on this environment. It is possible to change specific fields type from string to integer (or float). this can be done using the curl command in Elasticsearch.

Examples:

First you would get the mapping

```auto
curl -X GET "localhost:9200/graylog_1600/_mapping?pretty"

```

- [Update mapping API | Elasticsearch Guide [8.11] | Elastic](https://www.elastic.co/guide/en/elasticsearch/reference/current/indices-put-mapping.html)

Then adjust those fields as needed.

```auto
curl -X PUT "localhost:9200/graylog_1600/_mapping?pretty" -H 'Content-Type: application/json' -d'
{
  "properties": {
    "email": {
      "type": "integer "
    }
  }
}
'

```

Or use a Pipeline something like this.

- [Pipeline - Create field with value from another field - #2 by tmacgbay](https://community.graylog.org/t/pipeline-create-field-with-value-from-another-field/13355/2)

If your going the pipeline route @tmacgbay would know better then I would.

Hope that helps

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex016/uploads/graylog/original/3X/c/7/c7c09c6b5099570133d6502b83f50ba4430de5b6.png) [@system](https://community.graylog.org/u/system)\
**Post date:** [May 25, 2022, 11:38pm UTC](https://community.graylog.org/t/syslog-tcp-input-normalization/23774/5 "2022-05-25T23:38:24Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
