Configuring Content File
Info
This guide teaches how to configure Monitoring of files for content in text-based Files using the Nodinite Log File Parser Monitoring Agent.
Content File - Use this option to get alerts if the specified RegEx matches data in one or more files.
- Example: How to monitor file content
- Example: How to monitor the IIS (W3SVC) log files
- Example: How to monitor Nodinite Diagnostic files
There is another option, to Monitor files based on a correlation:
Correlated Events (Log File Event) - Use this option to correlate events spanning one or more log files containing a date and some Identifier to use correlating the set.
- Example: How to monitor correlated events
Please use RegEx101 or a similar tool, to test your RegEx expression. You must practice RegEx to use this agent.
Add 'Content File' monitoring configuration
The Content File tab holds an array with one or more configuration entries for a Content File Monitoring.
Here's an example on how to add and manage a 'Content File' Monitoring configuration.
Press the
Add
button to add one (or more) log file monitoring configurations:
Here's an example of a 'Content File' monitoring configuration; One accordion per entry.Repeat this step as required by your business need.
Configuring the Content File Monitoring entry
Click the Accordion to expand the configuration, then you can manage the content of the configuration.
General tab
Next, You need to enter some essential details for fields available in the General tab:
First, name the configuration, and provide some general properties for this configuration.
For each entry, the following properties can be set in the General Tab:
- Enabled - When checked, this Monitoring configuration is active
- Display name - A user-friendly name for this Monitoring configuration (mandatory)
- Description - The user-friendly short description for this Monitoring configuration
- Application ID - Associate this configuration with an Application. Ensure the ID is matching an entry in the Applications collection (mandatory)
Path tab
Next, You need to enter some details about the folder and type of files, available in the Path tab:
- Folder - The folder where to look for log files to monitor. Provide a valid path that the agent can reach
- Filter - To get a specific type of files, enter a matching RegEx-based expression
- Include child folders - When checked, include content in child folders
Filter
Below is a table with some common RegEx examples:
Filter | Example | Comment |
---|---|---|
\.xml$ |
XML Files | All XML files with suffix ".xml" |
\.txt$ |
Text Files | All text files with suffix ".txt" |
^ONLYME\.data$ |
Specific file | Only this file "ONLYME.data" |
^PrefixedFileName.*\.csv$ |
Matching a file name pattern | Files with prefix ^PrefixedFileName , and suffix .csv |
Match tab
Next, You need to enter some details about what to look for in the log files, available in the Match tab:
- Line contains - Enter the RegEx, to check if the line contains a match, 'X' start to check for date, value and error(s)
Time Options Tab
Next, You can manage the 'Clear Date Time' field and select a Time Option for files to be included in the Monitoring.
- Clear Date Time - Ignore issues that occurred before this time. Exclude files with an older created/modified time according to the 'File time option' setting and whether the files should include a date time. in ISO 8601 format (UTC or with date time offset) (yyyy-mm-ddThh:MM:ss.ms+/-timezoneoffset, for example '2019-05-17T13:37:00.123+02:00')
- File time option - Select the time option for files to be included for evaluation (using the time from the file system)
- Lines have a DateTime - When checked, you can use the Clear operation to ignore previous errors on a line by line basis. Otherwise, the Clear operation applies to each file
Lines have a DateTime
When you check the 'Lines have a DateTime' checkbox, the following properties can be set. If your log file have a date time, you can use a Remote Action ('Clear from here') to ignore previous errors in the set of files included according to the File time option.
- Match date - Enter the RegEx to extract the date and time (according to the format in the log file)
- Matched date groups - The RegEx match group numbers, or named groups (comma separated list). E.g. '^([0-9]{4}-[0-9]{2}-[0-9]{2}[T\s]?[0-9]{2}:[0-9]{2}:[0-9]{2}.[0-9]{3}([0-9]{2}:[0-9]{2})?)', use number 1
- Date Time Format (Optional) - Enter the Date Time format to use in the conversion to a DateTime, i.e yyyy-MM-dd HH:mm:ss.fffZ
- Use Agent time zone - Use this setting when the date and time lack the UTC 'Z' indicator or offset. When checked, assume the date-time is in the same time zone as the agent. Otherwise, assume the date-time is UTC
([0-9]{4}-[0-9]{2}-[0-9]{2}[T\s]?[0-9]{2}:[0-9]{2}:[0-9]{2}\.[0-9]{3}(\+[0-9]{2}:[0-9]{2})?)
File Time Option
- Created after - File time span
- Created after Clear Date Time
- Created after Clear Date Time - File time span - This is a helpful option for IIS Logs
- Evaluate all
- Last Created, one file only
- Last Modified, one file only
- Modified after Clear Date Time
- Modified after - File time span
Next Step
Add or manage a Monitoring Agent Configuration
Add or manage Monitor View
How to monitor Content File
How to monitor file content
How to monitor Nodinite Diagnostic files
How to monitor the IIS (W3SVC) log files
Related
Applications
Install Log File Parser Monitoring Agent
Monitoring
Monitoring Agents
Update