Log Parsing and Alert Setting

With HERO, Workload Automation log files can be parsed for an easier and faster analysis. You can activate this feature on all WA servers, except AIX servers. See Enabling Log Parsing.

From the Product log parsing rules management interface, you as an Administrator can create, edit, and delete log parsing rules, and activate them on selected servers. Alerts can be automatically set up according to your needs.

Log parsing rules can also be activated/deactivated at server level, in the server card. See Activating rules from the server card.

When an issue is detected into a log file, the bell on the server card turns into color (blue, yellow, or red) depending on the issue severity (informational, warning, or error). Click the bell to get information about the issue. See Monitoring Log Parsing rules.

 

 

On the HERO main page sidebar, select Product log parsing rules.

 

 

 

Here you can find predefined log parsing rules provided by HCL, that cover the most common issues with Workload Automation. Predefined rules can be viewed, or duplicated to obtain custom rules. Custom rules can be viewed/edited, duplicated, or deleted. With custom rules you can monitor any log file in your file system, not only WA log files.

You can activate each rule on one or multiple servers by clicking Select Servers. You can also select all servers in PROD or OTHER type environments with a single check mark.

 

 

 

When you activate a rule on a server (master or backup master), the rule applies to all the server components.

For each rule, the following information is displayed:

 

Creating custom rules

On the Log Parsing main page, click the button Create custom rule and complete the steps in the given order.

   

 

In the Rule settings tab, specify:

 

 

In the Target file paths tab, specify the file path (one or more) for the log file(s) that you want to monitor in the file system.

 

 

 

In the Conditions tab, specify one or more expression(s) that you want to match inside log files, the related matching criteria(s) (if regular or wildcard based), and the criteria specific error or warning message (optional).

Set also the number of expression occurrences in the log for the alert to be generated.

 

 

In the Alert settings tab, specify information needed to generate the alert in HERO UI and to notify the alert via email:

 

Enabling Log Parsing

You can enable Log Parsing on all WA servers, except AIX servers, in different ways:

In any case, to enable Log Parsing, HERO will install and run Filebeat binaries on the selected server.

Note: Filebeat is an open source data shipper for forwarding and centralizing log file data.

 

Activating rules from the server card

From the server card, under Monitoring > Log parsing rules, you can find all the available rules and verify which rules have been activated for your server.

 

 

 

You can activate/deactivate rules from here.

Click the Rules Management button to return to the Log Parsing main page.

 

 

Monitoring log parsing rules

From the server card, under Monitoring  >  Log Parsing rules, you can view the current status of the active Log Parsing rules.

Depending on the alert settings, the status of each rule for the server can be:

 

Log Parsing alerts are managed by HERO as server alerts: when an issue is detected in a log file, the bell on the server card turns into color (blue, yellow, or red) depending on the issue severity (informational, warning, or error).

Click the bell to get information about the alert.

In the Server Alerts panel, you can easily identify Log Parsing alerts because they are always assigned to the Server component and the description field contains information about the referenced log entry.

On the same panel, HERO might suggest runbooks to solve the issue.

 

 

 

 

Leave feedback