- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I need to filter specific applcation eventlogs from Windows Server.
I am using light weight forwarder
I set the configurations as below . I am unable to get the results as expected.
Please suggest any modifications needed ?
From Universal Forwarder:
inputs.conf
[WinEventLog:Application]
disabled = 0
index = Server1_idx
interval = 300
sourcetype = Server1_EventLogs
From Indexer:
props.conf
[Server1_Eventlogs]
SHOULD_LINEMERGE = false
MAX_TIMESTAMP_LOOKAHEAD=30
LINE_BREAKER = ([\r\n](?=\d{2}/\d{2}/\d{2,4} \d{2}:\d{2}:\d{2} [aApPmM]{2}))
REPORT-MESSAGE = wel-message, wel-eq-kv, wel-col-kv
KV_MODE=none
TRANSFORMS-FIELDS = strip-winevt-linebreaker
TRANSFORMS-set=setnull,setparsing
transforms.conf
[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
[setparsing]
REGEX =(?m)^EventCode=(5740|8112|1001)
DEST_KEY = queue
FORMAT = indexQueue
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I choose to go with scripted inputs. Here i can mention sourcetypes of my own.
using WMI Query i can filter specific eventlogs of my interest.
Sample:
Select * from Win32_NtLogEvent where LogFile = 'Application' AND EventCode ="xxx" OR EventCode="YYY"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I choose to go with scripted inputs. Here i can mention sourcetypes of my own.
using WMI Query i can filter specific eventlogs of my interest.
Sample:
Select * from Win32_NtLogEvent where LogFile = 'Application' AND EventCode ="xxx" OR EventCode="YYY"
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
No we can't as there are not valid attributes like source/sourcetype available for wineventlog in inputs.conf
We can however use
[Source::WinEventLog:Application] as source
Thanks
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
By default the chosen stanza name for an input is prepended with 'source::' , i think we don't want to explicitly mention
