Windows logs in LMlogs
Hi, happy new year ( i know)
I am trying to add a logfile into LMlogs and hope that any reader has searched and found a method to do this without the LM OpenTelemetry Collector.
In a Windows environment you dont want to install docker, kubernetes etc to just parse a logfile on a windows server.
I had hoped that LM has something and currently it is possible with the eventlog datasource but that is deprecated without having an alternative.
Anyone that has found a solution of has similar thoughts?
alangendijk
Posted 7 months ago·Last reply 6 months ago
2 comments
Andy_C
·6 months agoThe documentation for this is so old that LM still refers to other products that died years ago. FluentD as above is configured to send direct to the LM API directly and that's just another PITA if you have multiple servers to configure withe proxies, firewalls etc. You could install collectors everywhere but that's not really a solution for the same reasons.
Now to answer your question, if you need to monitor UTF16 logs like SQL logs or basically any MS app logfile , your only 'free' option is Vector Log Reader from Datadog. I have spent days trying to get the all the free versions to work and none do UTF16. You may not need UTF16 support now...but you will.
What you need to do is first set your collector to receive syslog, then configure Vector to read the logfiles and format the data to be syslog compatable, which is pretty simple , then send it to LM logs and do your queries / alerts etc in there.
David Quiroz
·6 months agoHey, happy New Year,
To forward any log file within Windows to LogicMonitor, you can use FluentD.
https://www.logicmonitor.com/support/lm-logs/sending-fluentd-logshttps://www.logicmonitor.com/support/supported-logs-and-ingestion-methods#:~:text=pull%20the%20logs-,Local%20Log%20Files,-Logs%20from%20a