Monitor file over SSH
You can create a data collector for monitoring data by using an SSH connection to a Microsoft Windows or Linux computer and retrieving event data.
This topic contains the following information:
Related topics
To collect data by using an SSH connection
- Navigate to Administration > Data Collectors > Add Data Collector
.
- In the Name box, provide a unique name to identify this data collector.
- From the Type list, select Monitor File over SSH.
Provide the following information, as appropriate:
Field
Description
Target/Collection Host
Target Host
Collection Host (Agent)
Type or select the collection host depending on whether you want to use the Collection Station or the Collection Agent to perform data collection.
The collection host is the computer on which the Collection Station or the Collection Agent is located.
By default, the Collection Station is already selected. You can either retain the default selection or select the Collection Agent.
Note: For this type of data collector, the target host and collection host are expected to have different values.
Collector Inputs
Server Name
Credentials
(Optional) Select one of the following options:
- Apply security credential to automatically populate the user name and password fields.
Then select the appropriate credential (profile) from the Available Credential list that you already configured under Administration > Credentials. - Provide Credential to manually add user name and password credentials.
Then enter the credentials in the User Name and Password fields.
You can also create a credential that uses the manually entered details by clicking Add Credentialnext to the Password field.
User Name
Provide the user name for connecting with the server from which you want to retrieve the data.
Note: This field is disabled if you applied a security profile earlier.
The product supports only password-based authentication for connecting with the SSH server.
Password
Provide the password for connecting with the server from which you want to retrieve the data.
Click Add Credential
, provide a credential name, and click OK to create a new credential (profile) from the credentials that you provided in the user name and password fields. Once this credential is created, it is displayed under Administration > Credentials.
Note: This field is disabled if you applied a security credential earlier.
Directory Path
Provide the absolute path of the data file.
To retrieve data files from subdirectories, do not provide the absolute path; instead, provide the path up to the parent directory.
Include sub-directories
Filename/Rollover Pattern
Specify the file name only, or specify the file name with a rollover pattern to identify subsequent logs.
You can use the following wild card characters:
- Asterisk (*)—Can be used to substitute zero or more characters in the file name.
- Question mark (?)—Can be used to substitute exactly one character in the file name.
Specifying a rollover pattern can be useful to monitor rolling log files where the log files are saved with the same name but differentiated with some variable like the time stamp or a number.
Note: Ensure that you specify a rollover pattern for identifying log files that follow the same data format (which means they will be indexed with the same data pattern).
Time Zone
Data Pattern
Pattern
Date Format
When you select a data pattern, the matching date format is automatically updated. However, you can specifically find date formats matching the timestamp in your data file.
Use one of the following methods to specify a date format:
- Filter the relevant data formats: Click Auto-Detect to find automatically find a list of matching data patterns and date formats. If no matching data patterns are found, a list of matching date formats is displayed. You can click each of the date formats displayed on the left, to see a preview of the sample records.
- Manually select a date format: Manually scan through the list available, and select one of the date formats available. Click Preview to see the sample records parsed.
Alternatively, from the Pattern list, select Free Text with Timestamp and click Preview to find the relevant data formats that match the file. - Create a new date format: If you are not satisfied with the results arising out of the date formats available, you can create a new date format. To do this, select the Create new Date Format option and manually enter the date format depending on the timestamp that you want to capture. For example, if your data file contains the timestamp, "28 Apr 2014 10:58:28", then your date format must be dd MMM yyyy HH:mm:ss.
Notes:
- If you select both – a pattern and a date format, then the date format specified takes precedence over the date format from the pattern that you selected. So the timestamp is indexed as per the specified date format, and the rest of the data is indexed as per the pattern.
- If you select only a date format, then the date format is used for indexing the timestamp, while the rest of the data is displayed in a raw format in your search results.
Poll Interval (mins)
Enter a number to specify the poll interval (in minutes) for the data collection (0 indicates that this is a one-time data collection).
By default, this value is set to 1.
Start/Stop Collection
(Optional) Select this check box if you want to start the data collection immediately.
- Apply security credential to automatically populate the user name and password fields.
- Click Create to save your changes.
What to do if an error occurs
To understand the troubleshooting scenarios related to this data collector, see Common-troubleshooting-issues with the Category filter set to Data collection.