Syntax for filters in check_eventlog
Posted: Thu Mar 03, 2016 9:33 am
Could you please point me some examples to use check_eventlog
I have found this link, https://outsideit.net/real-time-eventlog-monitoring/
couldn't understand it well. Looking at the NSCA settings configuration page on nsclient++ documentation.
there is a mention of scheduler in it, they say that the protocol cannot work without a scheduler? if so, how is this conig done without a scheduler ?
Could you point me to the syntax to write filter's . the nagvis agent that comes out of the box and included in Nagios XI crashes upon installation. Why is this not excluded from Nagios XI (5.2.3) would this be the same when we decide to buy nagios XI ?
Kindly answer me these above questions and post content or link where necessary.
[/settings/eventlog]
buffer size = 131072
debug = false
lookup names = true
syntax =
[/settings/eventlog/real-time]
debug = false
enabled = true
log = application,system
startup age = 30m
[/settings/eventlog/real-time/filters]
[/settings/eventlog/real-time/filters/default]
destination=NSCA
maximum age= 3d
ok message= Found no records in eventlog last three days.
syntax=%type% %id% %source%: %message%
[/settings/eventlog/real-time/filters/EVT_Application]
log= application
filter= level IN (error) AND (id NOT IN (1,3,10,12,13,23,26,33,37,38,58,67,101,103,104,107,108,110,112,274,502,511,1000,1002,1004,1005,1009,1010,1026,1027,1053,1054,1085,1101,1107,1116,1301,1325,1334,1373,1500,1502,1504,1508,1511,1515,1521,1533,1542,2019,2158,2636,2670,3001,3008,3012,3021,3032,3037,3042,3077,3079,3098,3119,3130,3131,3148,3159,4005,4102,4237,4621,5008,5009,5051,5124,5133,5605,5705,6001,6007,6016,6032,6044,6100,7043,7363,7735,7823,7827,7833,8193,8194,8196,8313,9001,10000,10005,10007,10862,10922,11317,12121,12289,12291,12298,12321,13793,13836,14197,14204,15000,16038,16041,16053,16058,16063,16066,16068,16082,16195,16391,16418,16419,16421,17187,17192,17204,17412,17898,18176,19269,19458,19954,19969,19972,20958,21061,22670,35698,35705,35710,35712,35716,35721,35726,37088,37090,37092,37095,37098,37119,37124,37225)) AND (id NOT IN (1509) OR source NOT IN ('Userenv')) AND (id NOT IN (1055) OR source NOT IN ('Userenv')) AND (id NOT IN (1030) OR source NOT IN ('Userenv')) AND (id NOT IN (1006) OR source NOT IN ('Userenv'))
severity= WARNING
ok message= Found no records in application eventlog last three days.
maximum age= 3d
I have found this link, https://outsideit.net/real-time-eventlog-monitoring/
couldn't understand it well. Looking at the NSCA settings configuration page on nsclient++ documentation.
there is a mention of scheduler in it, they say that the protocol cannot work without a scheduler? if so, how is this conig done without a scheduler ?
Could you point me to the syntax to write filter's . the nagvis agent that comes out of the box and included in Nagios XI crashes upon installation. Why is this not excluded from Nagios XI (5.2.3) would this be the same when we decide to buy nagios XI ?
Kindly answer me these above questions and post content or link where necessary.
[/settings/eventlog]
buffer size = 131072
debug = false
lookup names = true
syntax =
[/settings/eventlog/real-time]
debug = false
enabled = true
log = application,system
startup age = 30m
[/settings/eventlog/real-time/filters]
[/settings/eventlog/real-time/filters/default]
destination=NSCA
maximum age= 3d
ok message= Found no records in eventlog last three days.
syntax=%type% %id% %source%: %message%
[/settings/eventlog/real-time/filters/EVT_Application]
log= application
filter= level IN (error) AND (id NOT IN (1,3,10,12,13,23,26,33,37,38,58,67,101,103,104,107,108,110,112,274,502,511,1000,1002,1004,1005,1009,1010,1026,1027,1053,1054,1085,1101,1107,1116,1301,1325,1334,1373,1500,1502,1504,1508,1511,1515,1521,1533,1542,2019,2158,2636,2670,3001,3008,3012,3021,3032,3037,3042,3077,3079,3098,3119,3130,3131,3148,3159,4005,4102,4237,4621,5008,5009,5051,5124,5133,5605,5705,6001,6007,6016,6032,6044,6100,7043,7363,7735,7823,7827,7833,8193,8194,8196,8313,9001,10000,10005,10007,10862,10922,11317,12121,12289,12291,12298,12321,13793,13836,14197,14204,15000,16038,16041,16053,16058,16063,16066,16068,16082,16195,16391,16418,16419,16421,17187,17192,17204,17412,17898,18176,19269,19458,19954,19969,19972,20958,21061,22670,35698,35705,35710,35712,35716,35721,35726,37088,37090,37092,37095,37098,37119,37124,37225)) AND (id NOT IN (1509) OR source NOT IN ('Userenv')) AND (id NOT IN (1055) OR source NOT IN ('Userenv')) AND (id NOT IN (1030) OR source NOT IN ('Userenv')) AND (id NOT IN (1006) OR source NOT IN ('Userenv'))
severity= WARNING
ok message= Found no records in application eventlog last three days.
maximum age= 3d