Hello,
I have at the moment a Problem with the File Handling of the Windows Agent.
My Situation is:
Example:
File Content #1
Warning 03/09/2016 13:00 BSM/CSM SessionError "[138:742] Backup session "2016/03/09-51" of the backup specification ...
File Content #2
Warning 03/09/2016 14:00 BSM/CSM SessionError "[138:742] Backup session "2016/03/09-52" of the backup specification ...
The Agent does not recognize the new content… If I add a line everything is fine.
Agent Config:
[filelog|HPDPSessions]
directory=D:\Syslog\
include=*.log
charset=UTF-16LE
tags={"appname":"HPDPSessions"}
exclude_fields=hostname
Is there a workaround possible?
The agent only supports collecting appended log messages. Why are lines overridden?
The agent only supports collecting appended log messages. Why are lines overridden?
The software that creates this Log File has this behavior hardcoded...
No workaround to this today -- I suspect all other syslog agents would have the exact same problem, no?
Think so...
So anything that does not append to the end of the file is often considered a configuration change, not a log event. There are configuration management agents that monitor for the changes to any part of a file. The agent is for log events today, not configuration management. I hope this helps!