Content Packs

Windows Firewall Advanced Content Pack

Extract more Details from Windows Firewall File-Log

(ContentPack is attached)

 

- Blocked Connections by Source IP

- Blocked Connections by Destination IP

- Blocked Connections by Source Port

- Blocked Connections by Destination Port

- Blocked Connections by Protokoll

- Blocked Connections by Hostname

- Disabled / Enabled Firewall

Submitted by (@markus.kraus)
Add your comment

Voting

8 votes

Feature Requests

Log Insight Configuration Backup

Currently there is no method of backing up the Log Insight database or configuration files from the Log Insight Console. Providing a method of backing up manually, or on a scheduled time frame, would provide a benefit for off site backup, and disaster recovery solutions.

Submitted by (@patrickd)
3 comments

Voting

5 votes

Feature Requests

Alert when log source is not sending logs

Currently there is no alerting when Log Insight Master or Worker is not receiving logs/API events from its workers or agents. Part of the PCI compliance requires notification when a stoppage of logs is detected.

 

If this could be an alarm, or an automated email that is sent out, and have the ability to set certain thresholds (no logs within 30 minutes, 60 minutes, 3 hours, etc), that would be great.

Submitted by (@patrickd)
1 comment

Voting

52 votes

Feature Requests

Support globs for filelog directory option in Windows Agent

The agent should support globs (asterisk and wildcard) for folders. THe use case is IIS where multiple domains exist on the same server. Something like this

 

directory= E:\sitecoredata\*\Data\logs

include=log*.txt

So then I could make one that does them all type thing.

 

Globs are supported for files so this is an inconsistency in the product as well.

Submitted by (@jacob.curran)
22 comments

Voting

26 votes

Feature Requests

Log Insight Agent - send logs to multiple different destinations

Initial use-case: Our team supports the Operating System, while the Application Team supports their application. The Application Team already has their own Log Insight cluster setup to collect their application logs with the LI Agent. Because of this, we are unable to use the LI Agent to collect the Operating System logs. Ideally we would like to be able to send OS logs to our LI, and application logs to their LI. Forwarding ...more »

Submitted by (@joseph)
2 comments

Voting

5 votes

Feature Requests

Feature Request - Using Log Insight as a Forwarder and retaining source IP

We are using a third party SIEM. Due to the layout of the network and security requirements, we can only use log insight if it can forward all syslog and event log data to our SIEM. The problem is that the SIEM relies on the source IP of the system that generated the syslog data to be able to do its analytics. It creates a log source for each new syslog packet with a distinct IP address. We would like to use Log Insight, ...more »

Submitted by
1 comment

Voting

18 votes

Feature Requests

Authenticated webhook alerts

Today the webhooks alerting option sends an unauthenticated web POST to a URL. Enabling an authenticated post would open up the possibility to integrate directly with vRealize Orchestration (vRO), which can accept only authenticated posts.

Submitted by (@mdelatorre)
2 comments

Voting

8 votes

Feature Requests

Add version api / public

All software version info should be obtainable via API, currently private, should be public

Submitted by (@dgress)
2 comments

Voting

2 votes

Feature Requests

Ability to Set SSL=yes when installing windows agent with MSI

Currently unable to set SSL=yes when using the command line parameters. It is possible to set all the other important parameters, protocol, host, port but not SSL. This is especially important if your LI servers need to be set to SSL only.

 

Yes you could create a MST but this is a rather complicated solution to a simple problem.

Submitted by (@hywelburris)
2 comments

Voting

1 vote

Feature Requests

Resize existing Log Insight disks

It would be very handy if we could resize an already added disk (enlarge it). Login insight should then at a reboot resize the volume and start using the extra space! This works with new disks, but resizing existing disks is not supported today.

Submitted by (@hans.de.jongh)
6 comments

Voting

3 votes

Collection

Blacklisting/Discarding Events

From time to time there are occasions where i really would hope that blacklisting/discarding events is implemented in vRLI. For an example we currently are flooded with log entries from our 5.5 ESXi hosts which are coming from an "BUG" which is to be fixed in a patch without ETA. But there would be countless other examples too. I'm aware that there are possibilities to achieve that. One is with agents but for ESXi that ...more »

Submitted by (@rockaut)
3 comments

Voting

3 votes

Collection

LI API

My customer (DaVita) is looking for a way to query LI, check when the last time it received logs from connected ESXi hosts, and if the time is greater than x, automate the restart of syslog on the host.

 

Additional conversation around this topic can be found here: https://vmware-com.socialcast.com/messages/36422396?ref=stream

Submitted by (@rklumph)
1 comment

Voting

1 vote