Hi community,
We have been setting up some logs lately for our ISAM9 appliances by using the Rsyslog Forwarder for some of them and the System Alerts for some others.
While the System Alerts ones are pretty straight forward, we have been wondering if there was any documentation relative to the format/entries of those sent with the Remote Syslog. For example, we are using two different sources that we would like to fully understand before the receiver can start parsing them: Cluster and Runtime Messages (directed to two different ports).
Here are some logs sent by those two sources:
1) <47>Aug 5 09:55:22 HOSTNAME ISAM_CLUSTER_MSG 2019-08-05-09:55:17.867-04:00I----- 0x38A701C2 WebSEAL-Mgmt-API NOTICE wga cluster AMWARepFS.cpp 1084 0x7f96d7796700 WGAWA0450I A file system event has been detected: /var/isam/cluster/nodes/127.0.0.1 has been modified.
2) <47>Aug 5 10:10:10 HOSTNAME ISAM_RTE_MSG [8/5/19 10:10:08:025 EDT] 00012c18 SystemErr R The following mbean with type [WebSphere:type=ServletStats,name=IBM FIM Runtime Server.com.tivoli.am.fim.war.runtime.liberty.LibertyRuntimeServlet] isnt available
We can understand the beginning of those lines, up until the end of the Rsyslog header. From the second timestamp to the end of those messages, we would like to know what the different entries mean.
We feel like there would some documentation for this, and it's maybe right under our noses, but if anyone could redirect us in the right direction.
Thank you for your help
------------------------------
Regards
Francis Laframboise
------------------------------