32 lines
879 B
XML
32 lines
879 B
XML
<?xml version="1.0" encoding="utf-8"?>
|
|
<TimberWinR>
|
|
<Inputs>
|
|
<WindowsEvents>
|
|
<Event source="System,Application" binaryFormat="PRINT" />
|
|
</WindowsEvents>
|
|
<Logs>
|
|
<Log name="Syslogs" location="C:\Logs1\*.log" />
|
|
</Logs>
|
|
<IISW3CLogs>
|
|
<IISW3CLog name="Default site" location="c:\inetpub\logs\LogFiles\W3SVC1\*" />
|
|
</IISW3CLogs>
|
|
</Inputs>
|
|
|
|
<Filters>
|
|
<Grok>
|
|
<!--Single Tag-->
|
|
<Match field="Text" value="%{SYSLOGLINE}" />
|
|
<AddTag>rn_%{RecordNumber}</AddTag>
|
|
<AddTag>bar</AddTag>
|
|
</Grok>
|
|
<Mutate>
|
|
<Rename oldName="TimeGenerated" newName="timestamp"/>
|
|
</Mutate>
|
|
<Date field="timestamp" target="@timestamp" convertToUTC="true">
|
|
<Pattern>MMM d HH:mm:ss</Pattern>
|
|
<Pattern>MMM dd HH:mm:ss</Pattern>
|
|
<Pattern>ISO8601</Pattern>
|
|
</Date>
|
|
</Filters>
|
|
</TimberWinR>
|