Cannot find the origin and configuration of certain fields
Posted: Fri Oct 01, 2021 12:56 am
Hi team,
I was trying to collect logs from a file present in Windows server.
I found that certain fields like "port" were autogenerated and as per my best knowledge, I did not configure them. I wanted to know where it is being generated.
Also, while testing the filters, I once used "testlog" as the type field value in the Windows Event Log Input so that I would get logs with "type" field as "testlog". And then, I renamed the "type" field value from "testlog" to "evenlog", provided I verified, saved and applied it as global config.
I was expecting the field "type" to have value "eventlog" but still getting testlog. When none of my input and filter blocks make type as testlog, where is this value coming from
Please check with the following images for better understanding. Kindly provide your inputs on this.
Thanks in advance
I was trying to collect logs from a file present in Windows server.
I found that certain fields like "port" were autogenerated and as per my best knowledge, I did not configure them. I wanted to know where it is being generated.
Also, while testing the filters, I once used "testlog" as the type field value in the Windows Event Log Input so that I would get logs with "type" field as "testlog". And then, I renamed the "type" field value from "testlog" to "evenlog", provided I verified, saved and applied it as global config.
I was expecting the field "type" to have value "eventlog" but still getting testlog. When none of my input and filter blocks make type as testlog, where is this value coming from
Please check with the following images for better understanding. Kindly provide your inputs on this.
Thanks in advance