Supported Modules

Logpoint Agent (Standalone) supports the following categories of modules:

1. Extension Modules (xm_*)

Specialized log processing capabilities:

Module

Purpose

Documentation

xm_admin

Remote management

Remote Management

xm_charconv

Character set conversion

Character Set Conversion

xm_csv

CSV parsing

Delimiter-Separated Values

xm_fileop

File operations

File Operations

xm_filelist

File list operations

File Lists

xm_json

JSON formatting

JSON

xm_kvp

Key-value pair processing

Key-Value Pairs

xm_multiline

Multiline parsing

Multiline Parser

xm_pattern

Pattern matching

Pattern Matcher

xm_perl

Perl scripting

Perl

xm_rewrite

Event rewriting

Rewrite

xm_syslog

Syslog formatting

Syslog

xm_w3c

W3C log format

W3C

xm_xml

XML processing

XML

2. Input Modules (im_*)

Collect events from various sources:

Module

Purpose

Documentation

im_batchcompress

Batched compression input

Batched compression

im_exec

External program output

External programs

im_file

File-based log collection

File

im_fim

File integrity monitoring

File Integrity Monitoring

im_internal

Internal agent logs

Internal

im_kernel

Kernel logs

Kernel

im_mark

Periodic heartbeat

Mark

im_msvistalog

Windows Event Log

Event Log for Windows

im_null

Null input for testing

Null

im_perl

Perl-generated input

Perl

im_regmon

Windows Registry monitoring

Windows Registry Monitoring

im_ssl

TLS/SSL input

TLS/SSL

im_tcp

TCP input

TCP

im_udp

UDP input

UDP

im_uds

Unix domain sockets

Unix Domain Sockets

im_zmq

ZeroMQ input

ZeroMQ

3. Output Modules (om_*)

Forward logs to destinations:

Module

Purpose

Documentation

om_batchcompress

Batched compression output

Batched Compression

om_exec

Execute program

Program

om_null

Null output for testing

Null

om_perl

Perl-based output

Perl

om_ssl

TLS/SSL output

TLS/SSL

om_tcp

TCP output

TCP

om_udp

UDP output

UDP

om_udpspoof

UDP with IP spoofing

UDP with IP Spoofing

om_uds

Unix domain sockets

Unix Domain Sockets

om_zmq

ZeroMQ output

ZeroMQ

4. Processor Modules (pm_*)

Additional processing between input and output:

Module

Purpose

Documentation

pm_buffer

Buffer events

Buffer

pm_evcorr

Event correlation

Event correlator

pm_norepeat

De-duplication

De-duplicator

pm_null

Null processor

Null

pm_pattern

Pattern matching

Pattern Matcher


Helpful?

We are glad this guide helped.


Please don't include any personal information in your comment

Contact Support