Seq Documentation and Support

Welcome to the Seq documentation hub. You'll find comprehensive guides and documentation to help you start working with Seq as quickly as possible, as well as support if you get stuck. Let's jump right in!

Get Started    
Ask A Question

Questions

3

Is there a way to integrate the the seqcli ingest matching into sqelf or seq itself?

I am currently using docker and the gelf driver to output from NGINX into sqelf and then into seq itself. NGINX outputs log events like the below: 10.10.0.1 - - [06/May/2020:11:40:15 +0000] "GET /index.html HTTP/1.1" 200 510 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4131.0 Safari/537.36 Edg/84.0.505.0" "-" The docker gelf driver then outputs it as the below: {"@t":"2020-05-06T11:40:15.1150000Z","@mt":"10.10.0.1 - - [06/May/2020:11:40:15 +0000] \"GET /index.html HTTP/1.1\" 200 510 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4131.0 Safari/537.36 Edg/84.0.505.0\" \"-\"","@m":"10.10.0.1 - - [06/May/2020:11:40:15 +0000] \"GET /index.html HTTP/1.1\" 200 510 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/84.0.4131.0 Safari/537.36 Edg/84.0.505.0\" \"-\"","@i":"55a43b6f","image_name":"nginx","container_id":"e2e60c31d61de2f8ddadb96c58f5ad867950daa68b341d62d517ad1c031d6a4a","command":"nginx -g daemon off;","created":"2020-05-06T11:40:07.927934365Z","tag":"e2e60c31d61d","image_id":"sha256:602e111c06b6934013578ad80554a074049c59441d9bcd963cb4a7feccede7a5","host":"localubuntu","container_name":"nginx"} This means that within Seq the values of the actual NGINX log event aren't seen as individual values, only the docker assigned values are handled properly: https://imgur.com/a/OoTaFCa I am looking at possible alternatives (Docker outputting to file or syslog, then seqcli collecting and sending to seq), but is there a way I am missing? Thanks Alex

Posted by Alex Knight 4 months ago