The Log File Reader is configured through a YAML file located at:

  • <agent_home>/override_config/configuration_logfile_reader.yml or by default:
  • <agent_home>/default_config/configuration_logfile_reader.yml

This feature requires the LOG_FILE_READER licence module. Without it, the reader does not collect any metric.

Configuration file

The root key logfile-readers contains a list of reader definitions. Each reader name must be unique.

Reader definition

Field Type Required Default Description
name string yes Reader name, used in the metric path
directory string yes Absolute path of the directory to scan
file-name-regex string yes Java regex matched against the file name only (not the full path)
encoding string no UTF-8 Character encoding used to read the files
key-field object yes The column that decides whether a line produces a metric
extract-fields list no empty Additional columns appended to the metric path

Key field

Field Type Required Description
start int yes 0-based character position
length int yes Number of characters to extract
allowed-values list yes Only lines whose key matches one of these values produce a metric

Each entry in allowed-values:

Field Type Required Description
value string yes Raw value to match (after trimming)
alias string no If set, replaces the raw value in the metric path

Extract fields

Each entry in extract-fields:

Field Type Required Description
start int yes 0-based character position
length int yes Number of characters to extract

Extracted values are trimmed. A line too short to contain a declared field is ignored.

File name regex

The regex is matched against the file name only (not the directory path), and must match it entirely (full match, not a partial search).

It must also match the rotated file names, not just the active one. For example, if an application writes to app.log and rotation renames it to app.log.1, app.log.2, etc., the regex should be:

app\.log(\.\d+)?

Files whose name changes each period (e.g. daily_20260721.log) need nothing special — the regex is expected to match many files, and each one is read independently.

Warning: the regex must not match archival copies kept alongside a source that is still growing (e.g. app.log.bak). While both files hold the same content, the copy cannot be distinguished from a new file, and its lines would be reported a second time.

Example

Monitoring a batch scheduler that writes fixed-width daily log files:

logfile-readers:
  - name: CTM_DAILY
    directory: /opt/controlm/logs
    file-name-regex: daily_\d{8}.*\.log
    encoding: ISO-8859-1
    key-field:
      start: 11
      length: 4
      allowed-values:
        - value: "2"
          alias: OK
        - value: "3"
    extract-fields:
      - start: 45
        length: 10
      - start: 65
        length: 5

This reader:

  • scans /opt/controlm/logs for files matching daily_YYYYMMDD*.log
  • reads each line, extracts 4 characters starting at position 11 (the key field)
  • keeps only lines where the key is 2 or 3
  • for matching lines, also extracts two additional fields (positions 45-54 and 65-69)
  • produces metrics like Hpa|LogFile|CTM_DAILY|OK|fieldValue1|fieldValue2:value

A minimal reader with no extract fields:

logfile-readers:
  - name: APP_ERRORS
    directory: /var/log/app
    file-name-regex: app\.log
    key-field:
      start: 0
      length: 5
      allowed-values:
        - value: ERROR

This produces metrics like Hpa|LogFile|APP_ERRORS|ERROR:value, counting the number of ERROR lines per collection cycle.