Hello, please help me with understanding how zabbix process eventlog messages.
Let's say, I have about 40 Windows servers and most of them have at least two eventlogs I would like to track: Application and System. Many of these servers have messages in logs that have been collected for a few years.
Before yesterday I wasn't doing any monitoring of logs at all, but then I turned
item like eventlog[application] ON(ACTIVE) on all servers and here is what happened:
My system has completely queud up: Normaly, my zabbix queue would be 5-20 but now it has raised up to 400! As a result, very few information can come through this jam to the zabbix, even if is not related to logs. I checked, and as far as I can see, zabbix is collecting absolutely all info from these logs, despite its last year date - that's why queue is so enourmous.
Ok, lets say its normal. Zabbix is configured to keep history of logs for 30 days. question is, is zabbix going to download these old messages ONCE AGAIN from hosts after it deletes messages downloaded yesterday in 30 days time?
Hope you got the point... Please help me understand how to manage this log monitoring properly, cheers
Let's say, I have about 40 Windows servers and most of them have at least two eventlogs I would like to track: Application and System. Many of these servers have messages in logs that have been collected for a few years.
Before yesterday I wasn't doing any monitoring of logs at all, but then I turned
item like eventlog[application] ON(ACTIVE) on all servers and here is what happened:
My system has completely queud up: Normaly, my zabbix queue would be 5-20 but now it has raised up to 400! As a result, very few information can come through this jam to the zabbix, even if is not related to logs. I checked, and as far as I can see, zabbix is collecting absolutely all info from these logs, despite its last year date - that's why queue is so enourmous.
Ok, lets say its normal. Zabbix is configured to keep history of logs for 30 days. question is, is zabbix going to download these old messages ONCE AGAIN from hosts after it deletes messages downloaded yesterday in 30 days time?
Hope you got the point... Please help me understand how to manage this log monitoring properly, cheers
Also I see that it's only adding 2-3 entries per check! That means full log will be in zabbix db not earlier then tomorrow morning I think, no wonder my Zabbix was queued up since I asked to download logs from 40 servers at the same time with rate of 2-3 entries per check 

Comment