Log ParserThe Log Parser page defines log parsers and assigns them to selected machine IDs. Note: The log parsers are only active if they are subsequently assigned a log parser set using Assign Parser Sets. Log Monitoring The VSA is capable of monitoring data collected from many standard log files. Log Monitoring extends that capability by extracting data from the output of any text-based log file. Examples include application log files and syslog files created for Unix, Linux, and Macintosh operating systems, and network devices such as Cisco routers. To avoid uploading all the data contained in these logs to the KServer database, Log Monitoring uses parser definitions and parser sets to parse each log file and select only the data you're interested in. Parsed messages are displayed in Log Monitoring, which can be accessed using Agent > Agent Logs > Log Monitoring or the Agent Logs tab of the Machine Summary page or by generating a report using Reports > Logs > Log Monitoring. Users can optionally trigger alerts when a Log Monitoring record is generated, as defined using Assign Parsing Sets or Parser Summary. Log Monitoring Setup
The Log File Parsing Cycle The parsing of a log file is triggered whenever the log file is changed. In most cases this involves appending new text to the end of the file. To avoid scanning the entire log file from the beginning each time the file is updated, the agent parses log files as follows:
Note: The parsing of a log file is not a script event itself. Only a new configuration, or reconfiguration, using Log Parser, Assign Parser Sets or Parser Summary generates a script you can see in the Script History or Pending Script tabs of the Machine Summary page. Apply Click Apply to assign a selected log parser to selected machine IDs. Clear Click Clear to remove a selected log parser from selected machine IDs. Clear All Click Clear All to remove all log parsers from selected machine IDs. New... Select Edit... Select an existing log parser in the Log File Parser drop-down list and click Edit... to edit the log parser. Add Log Parser / Replace Log Parsers Select Add Log Parser to add a log parser to existing machine IDs. Select Replace Log Parsers to add a log parser and remove all other log parsers from selected machine IDs. | |||
Topic 3711: Send Feedback. Download a PDF of this online book from the first topic in the table of contents. |