Getting Data In
Highlighted

PROPS/TRANSFORMS.CONF

New Member

Hi - i am in the process of configuring routing 3 sourcetypes from 2 different directories to 3x indexers.

i have an access.log, secure.log and a ciscoironportweb.log ( i have renamed the sourcetypes)

the access and secure logs are being monitored from the same directory /opt/log/www*
the cisco log is in /opt/log/cisco1/ciscoironport_web.log

i have created the props.conf

[source::opt/log/ciscorouter1/ciscoironport_web.log]
TRANSFORMS-sourcetype = ciscoweblog

[weblog]
TRANSFORMS-a = access
log
TRANSFORMS-b = secure_log

TRANSFORMS

[accesslog]
SOURCE
KEY = MetaData:Sourcetype
REGEX = "status=*"
DEST_KEY = MetaData:Index
FORMAT = web

[securelog]
SOURCE
KEY = MetaData:Sourcetype
REGEX = "invalid user"
DEST_KEY = _MetaData:Index
FORMAT = security

[ciscoweblog]
SOURCEKEY = MetaData:Sourcetype
REGEX =
DEST
KEY = _MetaData:Index
FORMAT = network

from with in the REGEX fields i believe you can specify a string or a phrase which contains within the log.

but i am not entirely sure whether if what i am doing here is correct and whether how you can generate correct Regex's for these sourcetypes...

This is the monitored file for the network log

[monitor:///opt/log/ciscorouter1/ciscoironportweb.log]
disabled = 0
host
segment = 3
sourcetype = ciscoweblog
index = network

i have specified a single stanza to monitor both the access/secure logs.

[monitor:///opt/log/www/.log]
disabled = 0
hostsegment = 3
sourcetype = web
log
index = web

Can someone assist me to whether if i am in the right direction or completely wrong and how i can correct these conf files?

Thanks

0 Karma
Highlighted

Re: PROPS/TRANSFORMS.CONF

New Member

made a slight change to props

[ciscoweblog]
TRANSFORMS-route = ironportlog

[weblog]
LINE
BREAKER = ([\r\n])
MAXTIMESTAMPLOOKAHEAD = 22
SHOULDLINEMERGE = FALSE
TRANSFORMS-a = access
log
TRANSFORMS-b = secure_log
TRUNCATE = 256

0 Karma