Monitoring Linux and Windows Logs With The Graylog Collector-Bernd Ahlers
Monitoring Linux and Windows Logs With The Graylog Collector-Bernd Ahlers
Monitoring Linux and Windows Logs With The Graylog Collector-Bernd Ahlers
Bernd Ahlers
Graylog, Inc.
Bernd Ahlers
Graylog, Inc.
2003-10-11T22:14:15.003Z mymachine.example.com
evntslog - ID47 [exampleSDID@32473 iut="3"
eventSource="Application" eventID="1011"] BOMAn
application event log entry...
Regex
More regex
Even more regex
USERNAME [a-zA-Z0-9._-]+
USER %{USERNAME}
HOSTNAME \b(?:[0-9A-Za-z][0-9A-Za-z-]{0,62})(?:\.(?:[0-9A-Za-z][0-9A-
Za-z-]{0,62}))*(\.?|\b)
EMAILLOCALPART [a-zA-Z][a-zA-Z0-9_.+-=:]+
EMAILADDRESS %{EMAILLOCALPART}@%{HOSTNAME}
...
COMBINEDAPACHELOG %{COMMONAPACHELOG} %{QS:referrer} %{QS:agent}
Ask me anything!