You can configure the Log Insight Windows Agent to collect events from one or more log files.

Log in to the Windows machine on which you installed the Log Insight Windows Agent and start the Services manager to verify that the VMware vCenter Log Insight Agent service is installed.

1

Navigate to the program data folder of the Log Insight Windows Agent.

%ProgramData%\VMware\Log Insight Agent

2

Open the liagent.ini file in any text editor.

3

Add configuration parameters and set the values for your environment

Parameter

Description

[filelog|section_name]

A unique name for the configuration section.

directory

The full path to the log file directory.

include

(Optional) The name of a file name or a file mask (glob pattern) from which to collect data . You can provide values as a semicolon separated list. The default value is *, which means that all files are included.

exclude

(Optional) A file name or file mask (glob pattern) to exclude from collection. You can provide values as a semicolon separated list. The default value is empty, which means that no file is excluded.

event_marker

(Optional) A regular expression that denotes the start of an event in the log file. If omitted defaults to newline.

enabled

(Optional) A parameter to enable or disable the configuration section. The possible values are yes or no. The default value is yes.

charset

(Optional) The character encoding of the log files that the Log Insight Windows Agent monitors. The possible values are UTF-8, UTF-16LE, and UTF-16BE. The default value is UTF-8.

tags

An optional parameter to add custom tags to the fields of collected events. Define tags using JSON notation. Tag names can contain letters, numbers, and underscores. A tag name can only begin with a letter or an underscore and cannot exceed 64 characters. Tag names are not case sensitive. For example, if you use tags={"tag_name1" : "tag value 1", "Tag_Name1" : "tag value 2" }, Tag_Name1 will be ignored as a duplicate. You cannot use event_type and timestamp as tag names. Any duplicates within the same declaration are ignored.

[filelog|section_name]
directory=path_to_log_directory
include=regular_expression
event_marker=regular_expression
tags={"tag_name1":"Tag value 1", "tag_name2" : "tag value 2" } 
4

Restart the VMware Log Insight Agent service.

Note

Any change you make to the liagent.ini file requires a restart of the VMware Log Insight Agent service for the configuration change to take effect.

[filelog|vCenterMain]
directory=C:\ProgramData\VMware\VMware VirtualCenter\Logs
include=vpxd-*.log
exclude=vpxd-alert-*.log;vpxd-profiler-*.log
event_marker=^\d{4}-\d{2}-\d{2}[A-Z]\d{2}:\d{2}:\d{2}\.\d{3} 
[filelog|ApacheAccessLogs]
enabled=yes
directory=C:\Program Files (x86)\Apache Software Foundation\Apache2.2\logs
include=*.log
exclude=*_old.log
tags={"Provider" : "Apache"}
[filelog|MSSQL]
directory=C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Log
charset=UTF-16LE
event_marker=^[^\s]