The Log Insight Linux Agent collects events from log files on Linux machines and forwards them to the vRealize Log Insight server.

In a Linux system, applications can store log data in flat text files on the file system. The Log Insight Linux Agent can monitor directories and collect events from flat text log files.

The Log Insight Linux Agent runs as a daemon and starts immediately after installation. After installation, you can configure the following options:

Select the target Log Insight server to which the Log Insight Linux Agent forwards events.

Configure which directories the Log Insight Linux Agent monitors. By default the Log Insight Linux Agent is configured to collect messages and syslog files from the /var/log directory.

[filelog|messages]
directory=/var/log
include=messages;messages.?

[filelog|syslog]
directory=/var/log
include=syslog;syslog.?

The Log Insight Linux Agent supports the following distributions and versions.

RHEL 5 Update 10, RHEL 6 Update 5

SLES 11 SP3

Ubuntu 10.04 LTS, 12.04 LTS and 14.04 LTS

The Log Insight Linux Agent writes its own operation log files to /var/log/loginsight-agent/liagent_*.log. Log files are rotated when the Log Insight Linux Agent is restarted and when they reach a size of 10MB. At most 50MB of log files are kept.

To download the Log Insight Linux Agent package, navigate to the Administration page of the vRealize Log Insight Web user interface, in the Management section, click Agents, and click on the appropriate package link.