SzymonC We found what the issue was: the parser was written to accept syslog, but we were sending data via the Filebeat agent. We have corrected this, and now we are sending messages in syslog format, and the data is being read. However, the logs are not being parsed correctly, and in the tags, we see _grokparsefailure. It looks like this.
Additionally, Logstash is reporting the following error