ICAgent collects logs from hosts based on your specified collection rules, and packages and sends the collected log data to LTS on a log stream basis. You can view logs on the LTS console in real time.
Perform the following operations to configure ECS log ingestion:
You can choose not to select a host group in this step, but associate a host group with the ingestion configuration after you finish the procedure here. To do this, either:
Specify collection rules. For details, see Configurations.
Click Back to Ingestion Configurations to check the ingestion details. You can also click View Log Stream to view the log stream to which logs are ingested.
When you configure host log ingestion, the configuration details are as follows.
To import old-edition ingestion configurations to the new edition of log ingestion, click Import Old-Edition Configuration.
For example, /var/logs/**/a.log matches the following logs:
/var/logs/1/a.log /var/logs/1/2/a.log /var/logs/1/2/3/a.log /var/logs/1/2/3/4/a.log /var/logs/1/2/3/4/5/a.log
If a log collection path is similar to C:\windows\system32 but logs cannot be collected, enable the Web Application Firewall (WAF) and configure the path again.
/var/logs/1/a.log
/var/logs/2/a.log
/var/logs/service-1/a.log
/var/logs/service-2/a.log
/var/logs/service/a1.log
/var/logs/service/a2.log
If the collection path is set to a file name, the corresponding file is collected. Only text files can be collected. To query the file format, run file -i File name.
Blacklist filters can be exact matches or wildcard pattern matches. For details, see Collection Paths.
If you blacklist a file or directory that has been set as a collection path in the previous step, the blacklist settings will be used and the file or files in the directory will be filtered out.
Parameter |
Description |
---|---|
Log Type |
Log types include system, program, security, and startup. |
Offset from First Collection Time |
Example: Set this parameter to 7 to collect logs generated within the 7 days before the collection start time. This offset takes effect only for the first collection to ensure that the logs are not repeatedly collected. Max: 7 days. |
Event Severity |
The event severity can be information, warning, error, critical, or verbose. Filter and collect by Windows event level. Only Windows Vista or later is supported. |
Parameter |
Description |
---|---|
Log Format |
|
Log Time |
System time: log collection time by default. It is displayed at the beginning of each log event. NOTE:
|
Time wildcard: You can set a time wildcard so that ICAgent will look for the log printing time as the beginning of a log event.
NOTE:
If a log event does not contain year information, ICAgent regards it as printed in the current year. Example: YY - year (19) YYYY - year (2019) M - month (1) MM - month (01) D - day (1) DD - day (01) hh - hours (23) mm - minutes (59) ss - seconds (59) SSS - millisecond (999) hpm - hours (03PM) h:mmpm - hours:minutes (03:04PM) h:mm:sspm - hours:minutes:seconds (03:04:05PM) hh:mm:ss ZZZZ (16:05:06 +0100) hh:mm:ss ZZZ (16:05:06 CET) hh:mm:ss ZZ (16:05:06 +01:00) |
|
Log Segmentation |
This parameter needs to be specified if the Log Format is set to Multi-line. By generation time indicates that a time wildcard is used to detect log boundaries, whereas By regular expression indicates that a regular expression is used. |
Regular Expression |
You can set a regular expression to look for a specific pattern to indicate the beginning of a log event. This parameter needs to be specified when you select Multi-line for Log Format and By regular expression for Log Segmentation. |
The time wildcard and regular expression will look for the specified pattern right from the beginning of each log line. If no match is found, the system time, which may be different from the time in the log event, is used. In general cases, you are advised to select Single-line for Log Format and System time for Log Time.
On the LTS console, choose Log Ingestion in the navigation pane. Alternatively, access the Log Ingestion page by clicking Back to Ingestion Configurations when you finish configuring log ingestion.
If you have added a host using the old version, perform the following steps to view the host list: