Installation Guide
Important Information
TIBCO Documentation and Support Services
Installation
Requirements
General Security Considerations
User Account Considerations for Linux Systems
Supported Platforms
Hardware Requirements
Ports
Limitations
Prerequisites
Installing in Graphical Mode
Starting Graphical Mode
Installing Universal Collector
Uninstalling Universal Collector
Installing in Console Mode
Starting Console Mode
Installing Universal Collector
Uninstalling Universal Collector
Installing in Silent Mode
Starting Silent Mode
Installing Universal Collector
Uninstalling Universal Collector
Configuring LogLogic® Universal Collector Default Parameters
Starting and Stopping LogLogic® Universal Collector Service
Configuring the Real Time Access Parameters
Upgrading LogLogic Universal Collector from Earlier Version
Upgrading LogLogic® Universal Collector by using LogLogic® Management Center
User's Guide
Important Information
TIBCO Documentation and Support Services
Introduction
Overview
Collecting Logs
Real-Time File Logs
Collecting Single-line Messages
Log File Rotation
Collecting Multi-line Messages
Custom Multi-line Log Sources
Using Wildcard for File Names in Directory
Windows Event Logs
Originating IP of Log source for Forwarded Events
Local Collection
Remote Collection
Filtering Windows Event Logs
Syslog Logs
Filtering Syslog Logs
Remote Files
Configuring Remote File Default Parameters
LogLogic® Universal Collector Internal Logs
Creating and Configuring Log Sources
Adding a New Log Source
Copying a Log Source
Deleting a Log Source
Creating Multiple Log Sources
Creating a CSV File
Importing Log Sources
Creating a Complete Configuration
Editing Configuration General Settings
Adding a New Configuration
Open a Stored Configuration
Activate the Configuration
Save a Configuration
Editing Log Sources
Editing a Real-Time File Log Source
Editing the Forwarding Collection List
Edit Multiple Real-Time Log Sources
Editing a Windows Event Log Source
Edit Multiple Windows Event Log Sources
Editing a Syslog Log Source
Edit Multiple Syslog Log Sources
Editing a Remote File Log Source
Supported File Name Patterns
Edit Multiple Remote File Log Sources
Edit Different Types of Log Sources
Editing a Command Line Log Source
Sorting Log Sources
Create a New Tag
Apply a Tag
Remove a Tag
Sort Log Sources
Forwarding Logs
Forwarding Logs To Multiple Destinations
Creating a TCP or UDP Syslog Connection without Authentication
Creating a LogLogic LMI Connection without Authentication
Creating a Connection using Authentication and/or Encryption Mode
Step 1 Get a Root CA Certificate from your PKI
Step 2 Create a Certificate Signing Request
Using the Internal Tool
Using an OpenSSL
Step 3 Create a Valid LogLogic® Universal Collector Certificate by using a CA and OpenSSL
Step 4 Import the Certificate into *.ks or *.p12
Step 5 Configure the Forwarding Process
For *.ks
For *.p12
For *.pem
Configuring the Forwarding Process
Step 6 Enable Secure Connection
Managing the list of Forwardings
Copying a Forwarding
Deleting a Forwarding
Monitoring LogLogic® Universal Collector Activities
Starting UCMon Tool
Summary Screen
Status Screen
Log Source Status
Forwarding Connection Status
Metrics Screen
Log Source Metrics
Forwarding Connection Metrics
Trends Screen
Log Source Trends
Forwarding Connection Trends
RealTime Screen
Log Sources RealTime
Forwarding Connection RealTime
Exporting the Collection Status
Exporting the Trends Data
Command Line Interface
cert_mgt Manage the Security Certificates
uc_checkConf Check the Current Configuration
uc_createLogSources Import and Create Several Log Sources Simultaneously
uc_encryptPwd Encrypt Passwords for Windows Files
uc_monitor UCMon Tool
uc_reload Reload Configuration
uc_saveActiveConfAs Save an Active Configuration
uc_switchTo Make Configuration Active
Sample Configuration Files
UC Configuration uc.xml
LMI Connection uldp-sampleCommented.uldp.xml
LMI Connection uldp-sampleCommentedAuthJks.uldp.xml
LMI Connection uldp-sampleCommentedAuthPem.uldp.xml
LMI Connection uldp-sampleCommentedAuthPks12.uldp.xml
Log Sources file-sampleCommented.ls.xml
Log Sources syslog-sampleCommented.ls.xml
Log Sources wmi-sampleCommented.ls.xml
Regular Expressions
Event Output Format
IPv6 Support Matrix