Agent properties
This page lists the agent properties you can use to search for NXLog Agent instances in NXLog Platform.
You can create search expressions by combining one or more properties to find the NXLog Agent instances you need. This is useful when you are viewing agents or setting up auto-enrollment rules. To learn about the operators for building search expressions, see Selector operators.
| Property name | UI name | Description |
|---|---|---|
|
Timestamp when the agent first connected to NXLog Platform.
Example: |
|
|
IP address |
Source IP address and port number used by the agent to connect to NXLog Platform or null when the agent is offline.
Example: The port is optional when querying agents by address. The NXLog Platform UI doesn’t display the port. |
|
Arch |
CPU architecture of the agent’s host.
Possible values: |
|
Most recent data records sent by this agent to NXLog Platform. |
|
|
Information about the stored certificate, including the start and expiration time. |
|
|
Optional description associated with the agent. |
|
|
Either the actual content of the agent |
|
|
Synchronization status of the agent configuration and the corresponding configuration in NXLog Platform.
|
|
|
UUID of the user who created the configuration version assigned to the agent, or |
|
|
UUID of the configuration assigned to the agent, or |
|
|
Configuration |
Name of the configuration assigned to the agent, or |
|
Timestamp when the version of the configuration assigned to the agent was created, or |
|
|
Configuration |
Version number of the configuration assigned to the agent, or |
|
Contributes to |
Configuration status: |
|
Last offline |
Timestamp of the agent’s most recent transition from offline to online.
The value clears when the agent goes offline again.
In the agents table, the value appears as a relative time, such as |
|
CPU load |
Average CPU load of the agent process, measured since the process started. The NXLog Platform UI displays the value as a percentage rounded to two decimal places. |
|
CPU usage time of the agent process, measured in milliseconds since the process started. |
|
|
Egress MBps |
Data output rate in bytes per second. The NXLog Platform UI converts this to megabytes per second for display. |
|
Egress EPS |
Data output rate in events per second. |
|
Contributes to |
Enrollment status of the agent: |
|
Timestamp of the agent’s last enrollment in NXLog Platform.
Example: |
|
|
Same as |
|
|
Information on any errors related to the agent. For example, if the agent has an invalid configuration. |
|
|
Log processing rate in events per second (EPS). The NXLog Platform UI displays the value rounded to two decimal places. |
|
|
Number of file descriptors currently in use by the agent. |
|
|
Directories that can be used with the GetFile and PutFile web service requests. The name of the ACL is used in these requests together with the filename. ACLs are configured through the Remote Management extension. |
|
|
Name of the files associated with the agent, namely the certificate files and the configuration file. |
|
|
Content of the files associated with the agent, namely the certificate files and the configuration file. |
|
|
Synchronization information for the files associated with the agent, namely the certificate files and the configuration file. |
|
|
Synchronization status of the agent files: |
|
|
Same as |
|
|
Name |
The hostname of the machine where the agent is running, as reported by the agent. |
|
ID |
The UUID of the agent in UUID Version 1 format. The agent typically reports its ID, but NXLog Platform can generate or overwrite it. For example, to avoid duplication when you create a second agent instance by cloning a VM. |
|
Ingress MBps |
Data input rate in bytes per second. The NXLog Platform UI converts this to megabytes per second for display. |
|
Ingress EPS |
Data input rate in events per second. |
|
Names of all labels configured in the agent. Labels are configured through the Remote Management extension. |
|
|
Custom key-value pairs defined with supplementary details about the agent. For example, the display name or local contact information. Labels are configured through the Remote Management extension. |
|
|
Timestamp of the last event processed by the agent.
Example: |
|
|
The NXLog Platform IP address and port number to which the agent is connected or |
|
|
Memory usage |
Amount of RAM used by the agent in bytes. The NXLog Platform UI displays the value in megabytes or gigabytes. |
|
Module |
Names of the modules included in the agent configuration. |
|
Information about the modules included in the agent configuration. |
|
|
Same as |
|
|
Contributes to |
Connection status of the agent: |
|
OS |
Type of operating system where the agent is running.
Possible values: |
|
OS version |
Operating system type and version.
Example: |
|
|
|
|
Timestamp when the agent was set to persist data on disk, |
|
|
PID |
Process identifier of the agent instance.
Example: |
|
Last online |
Timestamp when NXLog Platform last requested data from the agent.
NXLog Platform polls agents once every 60 seconds.
Available for agents in any status.
In the agents table, the value appears as a relative time, such as |
|
Names of the routes included in the agent configuration. |
|
|
Information about the routes included in the agent configuration. |
|
|
Started |
Timestamp of the most recent agent start or restart.
Example: |
|
Contributes to |
The agent management status as |
|
Overall synchronization status of the agent files with NXLog Platform, determined by the
|
|
|
Number of threads the agent is using. |
|
|
Version |
Version of the agent.
Example: |
|
Information on any warnings related to the agent. For example, if the agent files are not synchronized with NXLog Platform. |
UI-only fields
Some fields shown in the NXLog Platform UI are not backed by a single agent property and so cannot be used directly in selectors.
| Field | Description |
|---|---|
|
The current date and time on the agent host machine. |
|
The agent’s stage in the deployment process. See Agent deployment state. |
|
A customizable name consisting of one or more agent fields. For more information, see Configure display names. |
|
Displayed in the agents table as the data output rate divided by the data input rate, computed as |
|
The agent’s connectivity to NXLog Platform. See Agent status. |