Log Collector
Introduction
Log Collector O11ySource is designed to gather, aggregate and store log data generated by various software applications, systems, or devices from Linux/Windows operating system. In the context of information technology, logs are records of events or activities that occur within a system. These events could include error messages, warnings, user actions, security events, and more.
Getting Started
Compatibility
Log Collector O11ySource can be configured to collect logs from Linux, Windows, AIX and Solaris systems.
Data Collection Method
Logs are collected using the probes of the OmniAgent.
Prerequisites
Inputs for Configuring Data Source
- Log Category Identifier: A unique identifier for the log category being configured
- Ignore Time (in mins): This option will ignores any files that were modified before the specified timespan.
- Is this multiline log: This enables to specify the multiline log-related settings.
- Pattern: Specifies the regular expression pattern to match. Depending on how you configure other multiline options, lines that match the specified regular expression are considered either continuation of a previous line or the start of a new multiline event. You can set the negate option to negate the pattern.
- Negate: Defines whether the pattern is negated.
- Match: Specifies how Logbeat combines matching lines into an event. The settings are before or after. The behavior of these settings depends on what you specify for negate.
- Storage Scope: Logs can be stored in two ways depending on how you want to organize and access them. When you choose to store logs per log type, each type of log will have its own dedicated table, making it easier to manage high-volume log types or apply different retention and query rules for each type. This is useful when log types are semantically different and must remain clearly separated. On the other hand, choosing to store logs per application groups multiple log types from the same application into a single table, which simplifies querying related logs together and works well when volumes are balanced across types and all logs share the same application context.
- Log Configurations: Log Configurations
- Host: Name/Address of the host where the application is running
- AWB Application: Select the AWB application from the dropdown list that corresponds to this device.
- Log Paths: Comma separated Absolute paths of the log files/directories to be monitored
- Advanced Configuration (YAML): Provide any additional advanced configurations related to these log files in YAML format.
- Log Collection Advanced Configuration (YAML): Provide any additional advanced configurations related to log collection from this device.
Firewall Requirement
To collect data from this O11ySource, ensure the following ports are opened:
| Source IP | Destination IP | Destination Port | Protocol | Direction |
|---|---|---|---|---|
| IP address of the Logs server | vuSmartMaps Collection/Ingress node IP | 443* | TCP | Inbound |
*Before providing the firewall requirements, please update the port based on the customer environment.
Configuring the Target
The probe must be installed and correctly configured to reliably collect data and send it to vuSmartMaps without failures.
Configuration Steps
Metrics Collected
The metrics are based on the input data collected.
