Page 1 of 1

Timestamp

Posted: Mon May 04, 2015 3:55 am
by joaase
Hi.

i have a small problems that i whant to understand why.

First question: when i select to se event "Last 7 Days" i get that i have from one of my panels 122 warnings and 224 error. then when i change time to "Last 30 Days" i only get 30 warning and 37 error. in my World i should have more warrning and error then i have 7 Days ago? i should have 122 warning and more.

Question 2: when i look in Log server on one specify error from a specify server, log server show me 119 events with that error base on event id and "Last 7 Days". Then i check event view from the server, with same "Last 7 Days", error and event ID, server show me 1690 error. why?

Best Regard
Joakim

Re: Timestamp

Posted: Mon May 04, 2015 9:52 am
by jolson
when i select to se event "Last 7 Days" i get that i have from one of my panels 122 warnings and 224 error. then when i change time to "Last 30 Days" i only get 30 warning and 37 error. in my World i should have more warrning and error then i have 7 Days ago? i should have 122 warning and more.
This is not expected behavior - when you do this, does your 'timestamp' filter change appropriately? Are you sure that Nagios Log Server isn't taking awhile to pull up all of your entries from the last 30 days? It can take some time to pull 30 days of logs out of elasticsearch, did you wait an appropriate amount of time?

What field do 'warning' and 'error' belong to - my guess is 'Opcode'?
when i look in Log server on one specify error from a specify server, log server show me 119 events with that error base on event id and "Last 7 Days". Then i check event view from the server, with same "Last 7 Days", error and event ID, server show me 1690 error. why?
Are you doing any index maintenance from the 'Backup and Maintenance' section of Nagios Log Server? If so, please show us your settings:
2015-05-04 09_51_54-Backup _ Maintenance • Nagios Log Server.png

Re: Timestamp

Posted: Wed May 13, 2015 2:40 am
by joaase
Lock this. i finns the solution by my self.

//Jocke

Re: Timestamp

Posted: Wed May 13, 2015 9:40 am
by jolson
What was the solution that you discovered? It would be good to know in case other users have a similar issue.

Re: Timestamp

Posted: Fri May 15, 2015 1:29 am
by joaase
The Solution was same that you all write for this case.

I find it out just Before i read it.

//Jocke

Re: Timestamp

Posted: Fri May 15, 2015 9:26 am
by jolson
Sounds good - I'll lock this thread up. Feel free to open a new one if you have any further questions or issues. Thanks!