<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ActiveGate SYSLOG - how to search for logs? in Log Analytics</title>
    <link>https://community.dynatrace.com/t5/Log-Analytics/ActiveGate-SYSLOG-how-to-search-for-logs/m-p/279269#M1360</link>
    <description>&lt;P&gt;Thanks for that info, though since we are on the Managed platform we cannot use those Open Pipeline features. The problem is not creating processing rules (though there are challenges there too), but rather in being able to filter the logs themselves. In an environment with a large volume of logs (as in ours) being able to filter to just the relevant logs is an important step in understanding what processing rules to then create. With all other logs I can at least filter by log source, but with the ActiveGate open pipeline syslogs I cannot.&lt;/P&gt;&lt;P&gt;I was able to add the dimension "dt.openpipeline.source" as a custom attribute which now allows me to filter on that, but I should not need to do that. This feature should enable this filtering natively. This seems broken to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jun 2025 16:11:06 GMT</pubDate>
    <dc:creator>cbaldi</dc:creator>
    <dc:date>2025-06-12T16:11:06Z</dc:date>
    <item>
      <title>ActiveGate SYSLOG - how to search for logs?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/ActiveGate-SYSLOG-how-to-search-for-logs/m-p/279168#M1354</link>
      <description>&lt;P&gt;We have started to use the built-in Open Telemetry module in the ActiveGate to collect syslogs. We see the logs appearing in the Log Viewer, however there does not appear to be a good way to create a log filter for these other than content. None of the dimensions from these syslog messages are filterable other than the generic loglevel and event.type. I expected to be able to filter on things like dt.openpipeline.source or dt.ingest.source.ip or even syslog.hostname but those are not available. Am I missing something? How can we create a filter for these syslog messages?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 06:41:51 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/ActiveGate-SYSLOG-how-to-search-for-logs/m-p/279168#M1354</guid>
      <dc:creator>cbaldi</dc:creator>
      <dc:date>2025-06-12T06:41:51Z</dc:date>
    </item>
    <item>
      <title>Re: ActiveGate SYSLOG - how to search for logs?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/ActiveGate-SYSLOG-how-to-search-for-logs/m-p/279189#M1355</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.dynatrace.com/t5/user/viewprofilepage/user-id/66140"&gt;@cbaldi&lt;/a&gt;&amp;nbsp;,&lt;BR /&gt;&lt;BR /&gt;i think what you need here is some log processing rules that gives you attributes/fields to filter things out.&lt;BR /&gt;It's better to use openpipeline if you can otherwise you can use classic log processing rules.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.dynatrace.com/docs/shortlink/lma-openpipeline" target="_blank"&gt;https://docs.dynatrace.com/docs/shortlink/lma-openpipeline&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Here are some examples on how you can create some rules:&lt;BR /&gt;&lt;A href="https://docs.dynatrace.com/docs/shortlink/lma-log-processing-examples" target="_blank"&gt;https://docs.dynatrace.com/docs/shortlink/lma-log-processing-examples&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Also, we have come up with some default log processors now that saves you from creating the rules. Goto openpipeline -&amp;gt; +pipeline -&amp;gt; select processor under 'technology bundle' and see below options&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="RohitBisht_0-1749699596490.png" style="width: 400px;"&gt;&lt;img src="https://community.dynatrace.com/t5/image/serverpage/image-id/28442i2CBEBB51D4B73D38/image-size/medium?v=v2&amp;amp;px=400" role="button" title="RohitBisht_0-1749699596490.png" alt="RohitBisht_0-1749699596490.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 03:41:36 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/ActiveGate-SYSLOG-how-to-search-for-logs/m-p/279189#M1355</guid>
      <dc:creator>RohitBisht</dc:creator>
      <dc:date>2025-06-12T03:41:36Z</dc:date>
    </item>
    <item>
      <title>Re: ActiveGate SYSLOG - how to search for logs?</title>
      <link>https://community.dynatrace.com/t5/Log-Analytics/ActiveGate-SYSLOG-how-to-search-for-logs/m-p/279269#M1360</link>
      <description>&lt;P&gt;Thanks for that info, though since we are on the Managed platform we cannot use those Open Pipeline features. The problem is not creating processing rules (though there are challenges there too), but rather in being able to filter the logs themselves. In an environment with a large volume of logs (as in ours) being able to filter to just the relevant logs is an important step in understanding what processing rules to then create. With all other logs I can at least filter by log source, but with the ActiveGate open pipeline syslogs I cannot.&lt;/P&gt;&lt;P&gt;I was able to add the dimension "dt.openpipeline.source" as a custom attribute which now allows me to filter on that, but I should not need to do that. This feature should enable this filtering natively. This seems broken to me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jun 2025 16:11:06 GMT</pubDate>
      <guid>https://community.dynatrace.com/t5/Log-Analytics/ActiveGate-SYSLOG-how-to-search-for-logs/m-p/279269#M1360</guid>
      <dc:creator>cbaldi</dc:creator>
      <dc:date>2025-06-12T16:11:06Z</dc:date>
    </item>
  </channel>
</rss>

