Submitted by (@markus.krausgmail.com1)

Windows Firewall Advanced Content Pack

Extract more Details from Windows Firewall File-Log

(ContentPack is attached)


- Blocked Connections by Source IP

- Blocked Connections by Destination IP

- Blocked Connections by Source Port

- Blocked Connections by Destination Port

- Blocked Connections by Protokoll

- Blocked Connections by Hostname

- Disabled / Enabled Firewall


11 votes

Submitted by (@patrickd)

Alert when log source is not sending logs

Currently there is no alerting when Log Insight Master or Worker is not receiving logs/API events from its workers or agents. Part of the PCI compliance requires notification when a stoppage of logs is detected.


If this could be an alarm, or an automated email that is sent out, and have the ability to set certain thresholds (no logs within 30 minutes, 60 minutes, 3 hours, etc), that would be great.


55 votes

Submitted by (

Datatype-aware field extraction

Sometimes log messages contain embedded data with a fixed standard format, like XML, JSON or CSV, either when logging about configuration/state information or when the messages aren't really logs. Attempting to parse out any of these formats with regular expressions is difficult (and in the case of XML, strongly discouraged), especially when the structure includes nesting, lists or esoteric quoting/escaping rules. For ...more »


8 votes

Submitted by (@hywelburris)

Ability to Set SSL=yes when installing windows agent with MSI

Currently unable to set SSL=yes when using the command line parameters. It is possible to set all the other important parameters, protocol, host, port but not SSL. This is especially important if your LI servers need to be set to SSL only.


Yes you could create a MST but this is a rather complicated solution to a simple problem.


1 vote

Submitted by (@jacob.curranacxiom.com1)

Support globs for filelog directory option in Windows Agent

The agent should support globs (asterisk and wildcard) for folders. THe use case is IIS where multiple domains exist on the same server. Something like this


directory= E:\sitecoredata\*\Data\logs


So then I could make one that does them all type thing.


Globs are supported for files so this is an inconsistency in the product as well.


27 votes

Submitted by

Feature Request - Using Log Insight as a Forwarder and retaining source IP

We are using a third party SIEM. Due to the layout of the network and security requirements, we can only use log insight if it can forward all syslog and event log data to our SIEM. The problem is that the SIEM relies on the source IP of the system that generated the syslog data to be able to do its analytics. It creates a log source for each new syslog packet with a distinct IP address. We would like to use Log Insight, ...more »


20 votes

Submitted by (@joseph)

Log Insight Agent - send logs to multiple different destinations

Initial use-case: Our team supports the Operating System, while the Application Team supports their application. The Application Team already has their own Log Insight cluster setup to collect their application logs with the LI Agent. Because of this, we are unable to use the LI Agent to collect the Operating System logs. Ideally we would like to be able to send OS logs to our LI, and application logs to their LI. Forwarding ...more »


7 votes


Submitted by (@rockaut)

Blacklisting/Discarding Events

From time to time there are occasions where i really would hope that blacklisting/discarding events is implemented in vRLI. For an example we currently are flooded with log entries from our 5.5 ESXi hosts which are coming from an "BUG" which is to be fixed in a patch without ETA. But there would be countless other examples too. I'm aware that there are possibilities to achieve that. One is with agents but for ESXi that ...more »


3 votes