<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Log monitoring v2 - Event log server side log entry filtering in Dynatrace Managed Q&amp;A</title>
    <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/195719#M2137</link>
    <description>&lt;P&gt;I am using Log Monitoring v2 in a Managed cluster. I need to monitor for specific events in the Windows Security Event Log on our application servers.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Windows Security Log generates a lot of events, and if I enable monitoring this on all my application servers I am going to reach the maximum # of log events per minute limitation on our cluster.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I configure server side log entry filtering in the ruxitagentloganalytics.conf so that we are only capturing the event IDs that we need?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have read this doc&amp;nbsp;&lt;A href="https://www.dynatrace.com/support/help/how-to-use-dynatrace/log-monitoring-v1/log-analytics-configuration-file" target="_blank" rel="noopener"&gt;https://www.dynatrace.com/support/help/how-to-use-dynatrace/log-monitoring-v1/log-analytics-configuration-file&lt;/A&gt;&amp;nbsp;and looked at the comments in the&amp;nbsp;ruxitagentloganalytics.conf.&amp;nbsp;&amp;nbsp;The bolded line below appears to show how to only capture 'INFO' level logs into Dynatrace,&amp;nbsp;but it is unclear how to filter by Event ID.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;#Server side log entry filtering&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;#EntryFilter=Process Group Id, log path, LAQL (&lt;A href="https://www.dynatrace.com/support/help/infrastructure/log-analytics/dynatrace-search-query-language" target="_blank" rel="noopener"&gt;https://www.dynatrace.com/support/help/infrastructure/log-analytics/dynatrace-search-query-language&lt;/A&gt;)&lt;/EM&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;#EntryFilter=0x0,Windows Application Log,INFO=======&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;#EntryFilter=0x201744FC09941B85,c:\ProgramData\CrashPlan\log\service.log.#,not INFO=======&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be appreciated.&amp;nbsp; Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 19 Jun 2023 08:37:34 GMT</pubDate>
    <dc:creator>AlanK</dc:creator>
    <dc:date>2023-06-19T08:37:34Z</dc:date>
    <item>
      <title>Log monitoring v2 - Event log server side log entry filtering</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/195719#M2137</link>
      <description>&lt;P&gt;I am using Log Monitoring v2 in a Managed cluster. I need to monitor for specific events in the Windows Security Event Log on our application servers.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The Windows Security Log generates a lot of events, and if I enable monitoring this on all my application servers I am going to reach the maximum # of log events per minute limitation on our cluster.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;How can I configure server side log entry filtering in the ruxitagentloganalytics.conf so that we are only capturing the event IDs that we need?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have read this doc&amp;nbsp;&lt;A href="https://www.dynatrace.com/support/help/how-to-use-dynatrace/log-monitoring-v1/log-analytics-configuration-file" target="_blank" rel="noopener"&gt;https://www.dynatrace.com/support/help/how-to-use-dynatrace/log-monitoring-v1/log-analytics-configuration-file&lt;/A&gt;&amp;nbsp;and looked at the comments in the&amp;nbsp;ruxitagentloganalytics.conf.&amp;nbsp;&amp;nbsp;The bolded line below appears to show how to only capture 'INFO' level logs into Dynatrace,&amp;nbsp;but it is unclear how to filter by Event ID.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;#Server side log entry filtering&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;#EntryFilter=Process Group Id, log path, LAQL (&lt;A href="https://www.dynatrace.com/support/help/infrastructure/log-analytics/dynatrace-search-query-language" target="_blank" rel="noopener"&gt;https://www.dynatrace.com/support/help/infrastructure/log-analytics/dynatrace-search-query-language&lt;/A&gt;)&lt;/EM&gt;&lt;BR /&gt;&lt;STRONG&gt;&lt;EM&gt;#EntryFilter=0x0,Windows Application Log,INFO=======&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;#EntryFilter=0x201744FC09941B85,c:\ProgramData\CrashPlan\log\service.log.#,not INFO=======&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any help would be appreciated.&amp;nbsp; Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 08:37:34 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/195719#M2137</guid>
      <dc:creator>AlanK</dc:creator>
      <dc:date>2023-06-19T08:37:34Z</dc:date>
    </item>
    <item>
      <title>Re: LogMonitoring v2 -Event Log Server side log entry filtering</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/195732#M2138</link>
      <description>&lt;P&gt;I think you look at the wrong doc - it's related to Log version 1 and you claim you use Log v2. What you need I believe is a log processing rules to FILTER OUT some events. Take a look here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.dynatrace.com/support/help/shortlink/lm-log-processing-commands" target="_blank"&gt;https://www.dynatrace.com/support/help/shortlink/lm-log-processing-commands&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 13:26:06 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/195732#M2138</guid>
      <dc:creator>Radoslaw_Szulgo</dc:creator>
      <dc:date>2023-04-24T13:26:06Z</dc:date>
    </item>
    <item>
      <title>Re: LogMonitoring v2 -Event Log Server side log entry filtering</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/195738#M2139</link>
      <description>&lt;P&gt;But log processing happens on server, so problem with "maximum # of log events per minute limitation on our cluster" will not be solved by that way. Agent will still send all eventlog events (Log Processing does not affect &lt;A class="" title="Understand how the volume of DDUs consumption is calculated for Dynatrace Log Monitoring." href="https://www.dynatrace.com/support/help/monitoring-consumption/davis-data-units/log-monitoring-consumption" target="_blank" rel="noopener"&gt;DDU&lt;/A&gt; consumption of log ingest).&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 08:45:13 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/195738#M2139</guid>
      <dc:creator>rastislav_danis</dc:creator>
      <dc:date>2022-10-04T08:45:13Z</dc:date>
    </item>
    <item>
      <title>Re: LogMonitoring v2 -Event Log Server side log entry filtering</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/195740#M2140</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/49268"&gt;@AlanK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I might not understand correctly but now there is a sophisticated way to drop the log events. You can go through with the below link already shared by&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/25371"&gt;@Radoslaw_Szulgo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.dynatrace.com/support/help/shortlink/lm-log-processing-commands" target="_blank"&gt;https://www.dynatrace.com/support/help/shortlink/lm-log-processing-commands&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/38440"&gt;@rastislav_danis&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To overcome the maximum log events limit, we used the same methodology to drop/filter out the events not required. In that way, we are receiving only the required events plus the random ingested log data termination is not taking out the important log events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Babar&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2023 13:26:38 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/195740#M2140</guid>
      <dc:creator>Babar_Qayyum</dc:creator>
      <dc:date>2023-04-24T13:26:38Z</dc:date>
    </item>
    <item>
      <title>Re: LogMonitoring v2 -Event Log Server side log entry filtering</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/195741#M2141</link>
      <description>&lt;P&gt;Then what I do is I use a log forwarder. For instance fluentd (&lt;A href="https://www.dynatrace.com/support/help/how-to-use-dynatrace/log-monitoring/acquire-log-data/stream-logs-fluentd-k8s" target="_blank"&gt;https://www.dynatrace.com/support/help/how-to-use-dynatrace/log-monitoring/acquire-log-data/stream-logs-fluentd-k8s&lt;/A&gt;)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And I filter in fluentd:&amp;nbsp;&lt;A href="https://docs.fluentd.org/filter" target="_blank"&gt;https://docs.fluentd.org/filter&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 04 Oct 2022 09:12:05 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/195741#M2141</guid>
      <dc:creator>Radoslaw_Szulgo</dc:creator>
      <dc:date>2022-10-04T09:12:05Z</dc:date>
    </item>
    <item>
      <title>Re: LogMonitoring v2 -Event Log Server side log entry filtering</title>
      <link>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/196485#M2142</link>
      <description>&lt;P&gt;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/25371"&gt;@Radoslaw_Szulgo&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;We had previously also registered &lt;A href="https://community.dynatrace.com/t5/Dynatrace-product-ideas/Log-monitoring-2-0-log-filter/idi-p/154627" target="_self"&gt;another&lt;/A&gt; product idea about this, but still didn't find a proper solution.&amp;nbsp; As a result we still haven't migrated yet from our ElasticSearch to Dynatrace Log Monitoring V2.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;The&amp;nbsp;&lt;EM&gt;EntryFilter &lt;/EM&gt;solution seems to be V1 related, so we cannot use that.&amp;nbsp; The FilterOut solution is processed at the server side, so we cannot use that either (because we have a massive amount of useless log entries that we don't want to send to Dynatrace across the network).&lt;BR /&gt;&lt;BR /&gt;Do I understand correctly that we need to write a custom Log Forwarder somehow, to allow the OneAgent to filter our log files (before sending them to Dynatrace managed servers or Saas)?&amp;nbsp; We would appreciate to get some tips about that!&lt;BR /&gt;&lt;BR /&gt;Thanks!&lt;BR /&gt;Bart&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 06:35:44 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Dynatrace-Managed-Q-A/Log-monitoring-v2-Event-log-server-side-log-entry-filtering/m-p/196485#M2142</guid>
      <dc:creator>bart_butenaers</dc:creator>
      <dc:date>2022-10-14T06:35:44Z</dc:date>
    </item>
  </channel>
</rss>

