The Log File Reader is configured through a YAML file located at:
-
<agent_home>/override_config/configuration_logfile_reader.ymlor by default: -
<agent_home>/default_config/configuration_logfile_reader.yml
This feature requires the LOG_FILE_READER licence module.
Without it, the reader does not collect any metric.
Configuration file
The root key logfile-readers contains a list of reader definitions. Each reader name must
be unique.
Reader definition
| Field | Type | Required | Default | Description |
|---|---|---|---|---|
name |
string | yes | Reader name, used in the metric path | |
directory |
string | yes | Absolute path of the directory to scan | |
file-name-regex |
string | yes | Java regex matched against the file name only (not the full path) | |
encoding |
string | no | UTF-8 | Character encoding used to read the files |
key-field |
object | yes | The column that decides whether a line produces a metric | |
extract-fields |
list | no | empty | Additional columns appended to the metric path |
Key field
| Field | Type | Required | Description |
|---|---|---|---|
start |
int | yes | 0-based character position |
length |
int | yes | Number of characters to extract |
allowed-values |
list | yes | Only lines whose key matches one of these values produce a metric |
Each entry in allowed-values:
| Field | Type | Required | Description |
|---|---|---|---|
value |
string | yes | Raw value to match (after trimming) |
alias |
string | no | If set, replaces the raw value in the metric path |
Extract fields
Each entry in extract-fields:
| Field | Type | Required | Description |
|---|---|---|---|
start |
int | yes | 0-based character position |
length |
int | yes | Number of characters to extract |
Extracted values are trimmed. A line too short to contain a declared field is ignored.
File name regex
The regex is matched against the file name only (not the directory path), and must match it entirely (full match, not a partial search).
It must also match the rotated file names, not just the active one. For example, if an
application writes to app.log and rotation renames it to app.log.1, app.log.2, etc.,
the regex should be:
app\.log(\.\d+)?
Files whose name changes each period (e.g. daily_20260721.log) need nothing special — the
regex is expected to match many files, and each one is read independently.
Warning: the regex must not match archival copies kept alongside a source that is still growing (e.g.
app.log.bak). While both files hold the same content, the copy cannot be distinguished from a new file, and its lines would be reported a second time.
Example
Monitoring a batch scheduler that writes fixed-width daily log files:
logfile-readers:
- name: CTM_DAILY
directory: /opt/controlm/logs
file-name-regex: daily_\d{8}.*\.log
encoding: ISO-8859-1
key-field:
start: 11
length: 4
allowed-values:
- value: "2"
alias: OK
- value: "3"
extract-fields:
- start: 45
length: 10
- start: 65
length: 5
This reader:
- scans
/opt/controlm/logsfor files matchingdaily_YYYYMMDD*.log - reads each line, extracts 4 characters starting at position 11 (the key field)
- keeps only lines where the key is
2or3 - for matching lines, also extracts two additional fields (positions 45-54 and 65-69)
- produces metrics like
Hpa|LogFile|CTM_DAILY|OK|fieldValue1|fieldValue2:value
A minimal reader with no extract fields:
logfile-readers:
- name: APP_ERRORS
directory: /var/log/app
file-name-regex: app\.log
key-field:
start: 0
length: 5
allowed-values:
- value: ERROR
This produces metrics like Hpa|LogFile|APP_ERRORS|ERROR:value, counting the number of
ERROR lines per collection cycle.