I'm using LogInsight 3.6 and i'm not interested in ingesting Windows system event logs at all.
I'm am however interested in ingesting the windows event-log channels of certain non-microsoft applications. No more, no less. That's all I need. The application is so nice to have it's own event-log channel so I don't need to muck about with logfiles etc. Just ingest the channel.
Inspired by a Blog-article about getting Veeam into LI, I got to work. And failed.
In the Blog they create a copy of the default Windows template and give it a name. They then tell the new template to disable all the standard Microsoft channels and create a new, custom channel X and enable it. That is the general idea I had also.
The problem is, I use a newer version of LI (v3.6, blog is at 3.3.1) and in 3.6 i cannot, for the life of me, copy a windows-template and save it.
I go to the dropdow, scroll all the way down, click the "copy icon" to the right of the dropdown-entry for the Windows template and enter the new name of the template. All just like in the LI 3.6 manual and in the blog.
I then give it a filter ("hostname contains applicationX.domain.local") and click "Save new group". But it cannot save it. It says: "Failed to save configuration" immediately.
The view jumps from "build" to "edit" and shows the same error that for each built-in section saying that the name is already defined in com.microsoft.windows.Microsoft etc. etc. (see attached screenshot)
To summarize: Copy a Windows template, give it a name, enter the filter, click on "Save new group" and bang, it cannot be saved. I have not even done anything else yet, just wanted to save the newly copied template.
So i'm stuck. Totally stuck.
My goal is to say "disabled" to all the standard channels (winlog | application / winlog | Security etc. etc.) and only add and enable a section "winlog | Custom" and enter the eventlog-channel that I want to ingest.
We have 7 application-servers and all we want is to ingest (just ingest) a very specific event-log channel and NOTHING else.
Any help would be greatly appreciated.