LogDistiller Log Types

LogDistiller comes with some log parsers bundled in its core distribution. Note that more log parsers can be found in LogDistiller Extension Center.

simple: Simple Line

This log type parses each line to a log event, with an unique attribute named text.

  <logtype id="simple">
    <attributes>
      <provided>logSource,text</provided>
      <!-- extension source="text" provides="xxx,yyy">(..) (.)</extension -->
    </attributes>
  </logtype>

syslog: Unix syslog facility

  <logtype id="syslog">
    <attributes>
      <provided>logSource,timestamp,host,program,pid,message</provided>
      <!-- extension source="message" provides="xxx,yyy">(..) (.)</extension -->
    </attributes>
  </logtype>

log4j-XML: log4j XMLLayout

  <logtype id="log4j-XML">
    <attributes>
      <provided>logSource,datetime,timestamp,level,logger,thread,message,NDC,throwable,locationInfo.class,locationInfo.method,locationInfo.file,locationInfo.line</provided>
      <!-- extension source="message" provides="xxx,yyy">(..) (.)</extension -->
    </attributes>
  </logtype>

jboss: JBoss application server

  <logtype id="jboss">
    <attributes>
      <provided>logSource,timestamp,timestamp.date,timestamp.time,level,logger,message,throwable,throwable.firstline,throwable.class</provided>
      <!-- extension source="message" provides="xxx,yyy">(..) (.)</extension -->
    </attributes>
  </logtype>

weblogic: Oracle (ex-BEA) Weblogic server

  <logtype id="weblogic">
    <param name="date.locale">en_US</param>
    <param name="date.format">MMM d, yyyy K:mm:ss a zz</param>
    <attributes>
      <provided>logSource,timestamp,severity,subsystem,machine,server,thread_id,transaction_id,user_id,message_id,message_text,stacktrace</provided>
      <!-- extension source="message_text" provides="xxx,yyy">(..) (.)</extension -->
    </attributes>
  </logtype>

oracle-alert: Oracle Database's alert.log

  <logtype id="oracle-alert">
    <attributes>
      <provided>logSource,timestamp,timestamp.day,timestamp.time,message</provided>
      <extension source="message" provides="ORA">(ORA-\\d+)</extension>
    </attributes>
  </logtype>