0 Replies Latest reply on Oct 20, 2014 2:43 PM by Jorge Xifra

    Weblogic data pattern

    Jorge Xifra
      Share This:

      I have a customer with BPPM. They are monitoring Weblogic. I´m starting to play with ITDA, and I got some logs from the customer.


      Here is an example of the log


      ####<Oct 16, 2014 12:24:17 AM ART> <Info> <JDBC> <wst3app01> <PORTALserver01> <[ACTIVE] ExecuteThread: '7' for queue: 'weblogic.kernel.Default (self-tuning)'> <<WLS Kernel>> <> <> <1413429857406> <BEA-001128> <Connection for pool "ReadLiferayPool" closed.>


      and here the Data pattern I created.


      %{Data:_ignore}\s*%{WeblogicTimestamp:timestamp}\s*\> \<*%{Data:1Severity}\> \<%{Data:2Subsystem}\> \<%{Data:3MachineName}\> \<%{Data:4ServerName}\> \<%{Data:5Msg1}\> \<%{Data:6UserID}\> \<%{Data:7Msg3}\> \<%{Data:8Msg4}\> \<%{Data:_ignore}\> \<%{Data:10MessageID}\> \<%{Data:11MessageText}\>*%{MultilineEntry:details}


      And this is the log format I use to decode it


      In this example, the message attributes are:

           Locale-formatted Timestamp,

      1. Severity,
      2. Subsystem,
      3. Machine Name,
      4. Server Name,
      5. Thread ID,
      6. User ID,
      7. Transaction ID,
      8. Diagnostic Context ID,
      9. Raw Time Value,
      10. Message ID, and
      11. Message Text.


      I´m attaching the data content-pack..


      Still work in progress...