After installation, the liagent.ini file contains pre-configured default settings for the Log Insight Windows Agent.

Log Insight Windows Agent liagent.ini Default Configuration

If you use non-ASCII names and values, save the configuration as UTF-8.

The final configuration is this file joined with settings from the server to form the liagent-effective.ini file.

You may find it more efficient to configure the settings from the server's agents page.

; Hostname or IP address of your Log Insight server / cluster load balancer. Default:

; Protocol can be cfapi (Log Insight REST API), syslog. Default:

; Log Insight server port to connect to. Default ports for protocols (all TCP):
; syslog: 514; syslog with ssl: 6514; cfapi: 9000; cfapi with ssl: 9543. Default:

; SSL usage. Default:
; Example of configuration with trusted CA:

; Time in minutes to force reconnection to the server.
; This option mitigates imbalances caused by long-lived TCP connections. Default:

; Logging verbosity: 0 (no debug messages), 1 (essentials), 2 (verbose with more impact on performance).
; This option should always be 0 under normal operating conditions. Default:

; Max local storage usage limit (data + logs) in MBs. Valid range: 100-2000 MB.

; Uncomment the following sections to collect these channels.
; The recommended way is to enable Windows content pack from LI server.








Protocol that the agent uses to send events to the vRealize Log Insight server. The possible values are cfapi and syslog. Use the default cfapi setting.



IP address or host name of the vRealize Log Insight virtual appliance.


9543, 9000, 6514, and 514

Communication port that the agent uses to send events to the vRealize Log Insight server. The default values are 9543 for cfapi with SSL enabled, 9000 for cfapi with SSL disabled, 6514 for syslog with SSL enabled and 514 for syslog with SSL disabled.



Enables or disables SSL. The default value is yes.

When ssl is set to yes, if you do not set a value for the port, the port is automatically picked up as 9543.



The maximum disk space in MB that the Log Insight Windows Agent uses to buffer events and its own logs.

When the specified max_disk_buffer is reached, the agent begins to drop new incoming events.



Defines the log details level. See Define Log Details Level in the Log Insight Agents.


Application, Security, System

The Application, Security, and System Windows Event Log channels are commented by default; the Log Insight Windows Agent does not collect logs from these channels.

See Collect Events from Windows Events Channels.