Collecting logs by using Logstash and Filebeat - Documentation for BMC Helix Log Analytics 22.4

Actual log:  "message": "Aug 10, 2022 11:37:14 AM com.bmc.ola.collection.collector.BaseCollector execute():410 \nINFO: Collector=<application name>Metrics_Collection Metrics_<hostname>.bmc.com, CollectionPollId=48,  2 events read and sent for indexing.",

Collected logs with metadata:

[{
  "@timestamp": "2022-11-21T09:40:23.183Z",
  "@metadata": {
    "beat": "filebeat",
    "type": "_doc",
    "version": "7.7.0"
  },
  "log": {
    "file": {
      "path": "C:\\Program Files\\BMC Software\\<application>\\<foldername>\\station\\collection\\logs\\collection_7.log"
    },
    "flags": [
      "multiline"
    ],
    "offset": 64668
  },
  "message": "Aug 10, 2022 11:37:14 AM com.bmc.ola.collection.collector.BaseCollector execute():410 \nINFO: Collector=ITDA Collection Metrics_Collection Metrics_<hostname>.bmc.com, CollectionPollId=48,  2 events read and sent for indexing.",
  "event.original": "Aug 10, 2022 11:37:14 AM com.bmc.ola.collection.collector.BaseCollector execute():410 \nINFO: Collector=ITDA Collection Metrics_Collection Metrics_<hostname>.bmc.com, CollectionPollId=48,  2 events read and sent for indexing.",
  
  "input": {
    "type": "log"
  },
  "ecs": {
    "version": "1.5.0"
  },
  "host": {
    "mac": [
      "00:50:56:8f:99:5f",
      "00:50:56:8f:cb:11"
    ],
    "hostname": "xxx-xxx-xxx1xx",
    "name": "xxx-xxx-xxx1xx",
    "architecture": "x86_64",
    "os": {
      "platform": "windows",
      "version": "10.0",
      "family": "windows",
      "name": "Windows Server 2019 Standard",
      "kernel": "10.0.17763.3406 (WinBuild.160101.0800)",
      "build": "17763.3406"
    },
    "id": "0000a0a0-0000-00aa-0000-0a0aa0aa00a0",
    "ip": [
      "10.111.11.111",
      "10.000.00.000"
    ]
  },
  "agent": {
    "type": "filebeat",
    "ephemeral_id": "0a000000-a0a0-0a00-000a-aa0a000a000a",
    "hostname": "xxx-xxx-xxx0xx",
    "id": "0000a0aa-a0aa-0a00-0000-0a0000000000",
    "version": "7.7.0"
  }
}]

You Might Also Like