Log Parser XML Reference
This page provides a complete reference for the log parser XML definition format used by the Log Watch subagent.
For how to set up and use log monitoring, see Log Monitoring.
Parser Element
The root <parser> element accepts these attributes:
| Attribute | Default | Description |
|---|---|---|
|
Parser name (for reference in metrics and logging) |
|
|
|
Process all rules even after a match (default: stop at first match) |
|
|
File check interval in milliseconds |
|
|
Time in milliseconds to wait for a newline before processing an incomplete last line as a complete record (0 = wait for newline) |
File Element
The <file> element specifies the log file to monitor.
If the file name starts with *, the rest of the name is treated as a Windows Event Log channel name instead of a file path (e.g., *Security); this form works on Windows only.
| Attribute | Description |
|---|---|
|
File encoding: |
|
Set to |
|
Detect broken pre-allocation (partial NUL padding) |
|
Use VSS snapshots for reading (Windows only) |
|
Keep file handle open between reads (default: |
|
Ignore file modification time for change detection |
|
Rescan file from beginning on each check cycle |
|
Follow symbolic links to target files |
|
Strip ANSI escape sequences from log lines |
File Path Macros
The <file> element path supports macro expansion:
-
Environment variables:
${ENV_VAR_NAME}— e.g.,${LOGDIR}/app.log -
strftime format codes:
%Y,%m,%d,%a, etc. — e.g.,C:\Windows\system32\dhcp\DhcpSrvLog-%a.log(day-of-week rotation) -
Shell command output: text enclosed in backticks is executed and replaced with stdout — e.g., `hostname`
.log
Parser Elements Summary
| Element | Description |
|---|---|
|
Path to the log file to monitor (supports strftime codes, environment variables, and backtick command expansion — see File Path Macros above) |
|
Container for rule definitions |
|
Individual matching rule |
|
Regular expression pattern to match against log lines |
|
Event to generate when the rule matches (numeric code or event name) |
|
Match condition on the incoming record’s log level (extended mode only) |
|
Match condition on the incoming record’s event ID or facility (extended mode only) |
|
Match condition on the incoming record’s source or tag (extended mode only) |
|
Match condition on the log name or syslog source address (extended mode only, server side) |
|
Rule label shown in trace output |
|
Activate or clear a context for multi-line matching |
|
Expose values captured from log lines as agent metrics |
|
Legacy form of |
|
Execute an agent action when the rule matches |
|
Container for reusable regex macro definitions / individual macro |
|
Container for time-based exclusion schedules / individual cron schedule |
Rule Element
The <rule> element accepts these attributes:
| Attribute | Default | Description |
|---|---|---|
|
Only activate this rule when the named context is active |
|
|
Rule name (used to restore per-rule check and match counters when the parser configuration is reloaded) |
|
|
(auto-generated) |
Rule GUID; generated automatically if not specified |
|
|
Force-stop rule processing after this rule matches, even if |
|
|
Do not save matched records to the database (used with syslog parser) |
Match Element
The <match> element uses PCRE (Perl-Compatible Regular Expressions) and supports these attributes:
| Attribute | Default | Description |
|---|---|---|
|
|
Case-insensitive regex matching |
|
|
Match lines that do NOT match the pattern |
|
|
Number of matches required before generating event (0 = immediate) |
|
|
Time window in seconds for counting repeats |
|
|
Reset repeat counter when threshold is reached |
|
|
Turn the rule into an absence rule: it fires when no matching record arrives within |
|
|
Time in seconds without a matching record after which an absence rule fires |
|
|
Interval in seconds between repeated alerts while the absence condition persists |
Both repeatCount and repeatInterval must be greater than 0 to enable repeat checking.
Named Event Parameters
PCRE named capture groups in the match pattern become named parameters of the generated event:
<match>user (?<username>\S+) logged in from (?<ipaddr>\S+)</match>
The captured values can then be referenced in EPP rules, alarms, and notifications as %<username> and %<ipaddr>.
Unnamed capture groups are automatically named group_1, group_2, and so on, and reach the event as named parameters — reference them as %<group_1>, %<group_2>, etc. (there is no positional parameter list).
When editing the XML directly, < and > must be escaped as < and > (the management client editor does this automatically).
Context Element
The <context> element controls multi-line matching.
The context name is the element text (used in the context attribute of other rules):
<context action="set" reset="auto">STARTUP</context>
| Attribute | Description |
|---|---|
|
|
|
Context reset mode, only valid with |
Event Element
The <event> element defines the event to generate when the rule matches.
The element content is either a numeric event code or an event name:
<event tag="ssh">MY_CUSTOM_EVENT</event>
The optional tag attribute sets the tag of the generated event.
Severity Element
The <severity> element is a rule match condition on the incoming record’s log level, evaluated only in extended mode (syslog, Windows Event Log, and OpenTelemetry log parsing).
<level> is an exact alias for <severity>.
The value is a bitmask where each log level contributes bit 2^severity; the rule matches only if the bit corresponding to the record’s level is set.
It does not set the severity of the generated event.
Id and Facility Elements
<id> and <facility> are aliases for the same rule match condition, evaluated only in extended mode.
The element text is a single number or a range in the form start - end, matched against the record’s event ID (Windows Event Log) or facility (syslog).
Source and Tag Elements
<source> and <tag> are aliases for the same rule match condition, evaluated only in extended mode.
The element text is a case-insensitive glob pattern matched against the record’s source (Windows Event Log) or tag (syslog).
Description Element
The <description> element is a rule label shown in trace output for troubleshooting.
It has no effect on the generated event.
Metric Element
The <metrics> element extracts values from log lines and exposes them as agent metrics:
<metrics>
<metric group="1">metric.name</metric>
</metrics>
-
group(default: 1) — which regex capture group’s value to use as the metric value -
push(default: false) — push the value via data push instead of making it a queryable metric
A legacy <push> element is also supported: <push group="1">metric.name</push>.
Agent Action Element
The <agentAction> element triggers an agent action when a rule matches:
<agentAction action="action_name">arguments</agentAction>
The action attribute specifies the agent action name to invoke.
The element text is split on whitespace into an argument list (quoting is not supported); the arguments are passed to the agent action, where they can be referenced as $1 through $9 in the action’s command line.
Log Name Filter Element
The <logName> element is a rule match condition evaluated only in extended mode, on the server side:
<logName>*Security*</logName>
The value is a wildcard pattern matched against:
-
the event channel name, for the agent-side Windows event log parser (scopes the rule to specific channels when the parser monitors several);
-
the log name, for the server-side Windows event log parser (events forwarded by agents);
-
the source IP address of the message, for the server-side syslog parser (the same record field carries the source address there).
It is never evaluated for file parsers.
Exclusion Schedule Element
The <exclusionSchedules> element suspends log parsing during specific time periods:
<exclusionSchedules>
<schedule>* 2-4 * * *</schedule>
</exclusionSchedules>
The <schedule> element uses cron format.
Macros Element
The <macros> element defines reusable regex patterns:
<macros>
<macro name="IP">(?:\d{1,3}\.){3}\d{1,3}</macro>
</macros>
Macros are referenced with @{MACRO_NAME} syntax in match patterns.
Use \@ to include a literal @ character.
Log Parser Provided Metrics
The Log Watch subagent provides metrics about monitored log files:
| Metric | Description |
|---|---|
|
Number of records matched by the parser |
|
Total records processed by the parser |
|
Parser status |
|
Current value of a metric defined in a |
|
Timestamp of the last update of a metric defined in a |
|
Current value of a metric defined in a |
|
Timestamp of the last update of a metric defined in a |
The MatchedRecords, ProcessedRecords, and Status metrics accept an optional second argument with the monitored file name, e.g., LogWatch.Parser.Status(syslog,/var/log/messages).
Available lists:
| List | Description |
|---|---|
|
Names of all defined parsers |
|
Names of all metrics defined in parsers |
Available tables:
| Table | Instance column | Description |
|---|---|---|
|
NAME |
All metrics defined in parsers with their current values |