Ad Widget

Collapse

Windows Event Logs

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • plop
    Junior Member
    • Mar 2009
    • 12

    #1

    Windows Event Logs

    Hello,

    I am experimenting Zabbix for about a week now, it fits perfectly in my infrastructure.

    But I have some trouble to use Windows Event Logs monitoring.

    I've configured everything following this instructions.

    I try to monitor 2 Windows 2003 (Standard 32b, fr-FR), with the latest agent found here. Everything is fine but the event logs. In "Overview", triggers stay grey, and nothing to see in the last 500 events view.

    Do you have some ideas about this issue ?

    Thank you in advance for your help.
    Last edited by plop; 20-08-2010, 09:57. Reason: Problem solved
  • gospodin.horoshiy
    Senior Member
    • Sep 2008
    • 272

    #2
    Try to check agent's log in debug mode
    Zbx 2.0.4 on Debian and MYSQL5 on Ubuntu Server 64bit 8.04,
    200+ Win Agents, 50+ Linux Agents, 150+ Network Devices

    Comment

    • plop
      Junior Member
      • Mar 2009
      • 12

      #3
      Hello,

      Thanks for you answer.

      I've started the agent in debug mode. I don't see any reference to Event Logs in the debug file.

      Do I have to make some client-side modifications to enable event logs monitoring ?
      Last edited by plop; 23-03-2009, 17:26.

      Comment

      • gospodin.horoshiy
        Senior Member
        • Sep 2008
        • 272

        #4
        No no configuration required
        Well, if you don't see any references, then I think that item not assigned to the host(agent) for some reason. Is it enabled or disabled ?
        In other case, you would see something like NOT_SUPPORTED or other errors related to eventlog[application] for example in your agent log. Try digging from server's side

        Is it active or passive agent?
        Last edited by gospodin.horoshiy; 23-03-2009, 17:41.
        Zbx 2.0.4 on Debian and MYSQL5 on Ubuntu Server 64bit 8.04,
        200+ Win Agents, 50+ Linux Agents, 150+ Network Devices

        Comment

        • krimson
          Member
          • Sep 2008
          • 49

          #5
          Are you sure you enabled active checks in your zabbix agent configuration and set the hostname of the monitored server ? The hostname should match the hostname you defined in the zabbix database (case sensitive !).

          Comment

          • plop
            Junior Member
            • Mar 2009
            • 12

            #6
            Hello,

            First, thank you for your help.

            I've checked, the agent seems correct :
            Code:
            ZABBIX agent (active)
            The hostname value is the same on both server and client.

            I guess I'm doing wrong, but I can't figure where...

            Comment

            • Ranjit
              Junior Member
              • Mar 2010
              • 5

              #7
              I am having the same exact issue.

              In the Overview screen, the row that is for collecting logs stays dark grey. On clicking the cell and then "Events", it takes me to the Events page and there is no data here.

              However, the Status of the Item as reported by the Agent indicates there are no problems.

              Any clues?

              Comment

              • Ranjit
                Junior Member
                • Mar 2010
                • 5

                #8
                Ok, i got this working finally and has to do with the agent side config.

                The Hostname parameter in the zabbix_agentd.conf has to be configured properly and should be the exact name that one gives while *creating host on zabbix server* . This config has to be properly for all Active Checks.

                Unfortunately, there is nothing logged in the agent side log as well even with Debug=4. And more as a problem, that is per design. The Zabbix Server will ask the agent to do the active checking only if the Hostname in the agent config is the same as the name of the Host configured on the Server.

                At its basic level, this misunderstanding comes due the over-usage of words like host and server. In the Zabbix context, depending on what you are talking about, a host can mean,
                - a system
                - a FQDN
                - a Zabbix name for a system (this is the problem) and so on.

                Similarly, probably the Zabbix Server should be called Zabbix CMS or something similar.

                When i am done with all the full config, will blog the whole process.

                Comment

                • plop
                  Junior Member
                  • Mar 2009
                  • 12

                  #9
                  Hello,

                  This problem is back, as I have some time to experiment Zabbix 1.8.2.

                  I'm not able to get windows events...

                  The configuration of zabbix_agentd.conf seems to be correct, active checks enabled, correct case-sensitive hostname :
                  Code:
                  DebugLevel=0
                  LogFile=C:\Program Files\Zabbix Agent\Zabbix_agentd.log
                  EnableRemoteCommands=1
                  Server=192.168.40.10
                  Hostname=srv-vcm1
                  ListenPort=10050
                  ServerPort=10051
                  StartAgents=5
                  I see nothing in both agent logs or server logs.

                  My item is :
                  eventlog[Application]

                  The associated trigger :
                  {A-Journaux_Windows:eventlog[Application].logseverity(4)}=4

                  Why don't Zabbix have a easier way to monitor Windows event logs ? I mean, Microsoft Windows is not very rare in IT environments, why keep it so complicated... But I like to have so much choice.

                  I'm very close to the perfect monitoring solution, if anybody can help me...

                  Thank you in advance.
                  Last edited by plop; 05-08-2010, 11:52.

                  Comment

                  • zalex_ua
                    Senior Member
                    Zabbix Certified Trainer
                    Zabbix Certified SpecialistZabbix Certified Professional
                    • Oct 2009
                    • 1286

                    #10
                    You should change the Host name into zabbix WEB-interface from "A-Journaux_Windows" to "srv-vcm1".
                    This is your mistake.

                    Comment

                    • plop
                      Junior Member
                      • Mar 2009
                      • 12

                      #11
                      Originally posted by zalex_ua
                      You should change the Host name into zabbix WEB-interface from "A-Journaux_Windows" to "srv-vcm1".
                      This is your mistake.
                      Thank you for your help.

                      Sorry, but the hostname is right, I've checked it. I've just pasted the extract from the template... but the final configuration reflects the correct hostname.

                      Do you have some other clues ?

                      Comment

                      • hulting74
                        Member
                        • Nov 2008
                        • 30

                        #12
                        Hi

                        I have this working with the template i created, you can download it here. (bottom of the page, which also includes some screendumps) :-)

                        http://www.zabbix.com/wiki/howto/mon...ndows_eventlog

                        /S

                        Comment

                        • plop
                          Junior Member
                          • Mar 2009
                          • 12

                          #13
                          Originally posted by hulting74
                          Hi

                          I have this working with the template i created, you can download it here. (bottom of the page, which also includes some screendumps) :-)

                          http://www.zabbix.com/wiki/howto/mon...ndows_eventlog

                          /S
                          Thank you for your help.

                          I have reproduced exactly the same configuration, but I can't see any logs.

                          I have some questions about your indications. On the triggers, which one is the correct syntax :
                          Code:
                          {srv-vcm1:eventlog[System].logseverity(0)}=4
                          or
                          Code:
                          {srv-vcm1:eventlog[System].logseverity(4)}=4
                          ?
                          Your screenshots differs from your text indications.

                          I've tried both, but I see no changes.

                          I can't import the XML file you provide, it gives me the following error :
                          Code:
                          XML file contains errors. Fatal Error 5: Extra content at the end of the document [ Line: 335 | Column: 2 ]
                          If I remove the last line
                          Code:
                          </zabbix_export>
                          it imports successfully, but no new items or triggers are created.


                          Thanks everyone for your help.

                          Looking forward to reading from you.

                          Comment

                          • zalex_ua
                            Senior Member
                            Zabbix Certified Trainer
                            Zabbix Certified SpecialistZabbix Certified Professional
                            • Oct 2009
                            • 1286

                            #14
                            Originally posted by plop

                            I have some questions about your indications. On the triggers, which one is the correct syntax :
                            Code:
                            {srv-vcm1:eventlog[System].logseverity(0)}=4
                            or
                            Code:
                            {srv-vcm1:eventlog[System].logseverity(4)}=4
                            ?
                            Your screenshots differs from your text indications.

                            I've tried both, but I see no changes.
                            Indeed, the difference should not be.
                            According to the documentation
                            http://www.zabbix.com/documentation/...onfig/triggers

                            ARGUMENT in function 'logseverity' is ignored.

                            I've tested it personally - everything works according to the documentation.
                            In fact, on the forum are many examples where users are in parentheses use different numbers and think that they mean something. But they are wrong. There must be a either a number, I propose to use 0.
                            This I corrected recently these errors on Wiki. Now there is correct.
                            http://www.zabbix.com/wiki/howto/mon...ndows_eventlog

                            Comment

                            • plop
                              Junior Member
                              • Mar 2009
                              • 12

                              #15
                              Originally posted by zalex_ua
                              Indeed, the difference should not be.
                              According to the documentation
                              http://www.zabbix.com/documentation/...onfig/triggers

                              ARGUMENT in function 'logseverity' is ignored.

                              I've tested it personally - everything works according to the documentation.
                              In fact, on the forum are many examples where users are in parentheses use different numbers and think that they mean something. But they are wrong. There must be a either a number, I propose to use 0.
                              This I corrected recently these errors on Wiki. Now there is correct.
                              http://www.zabbix.com/wiki/howto/mon...ndows_eventlog
                              Thank you for your help.

                              I've modified every trigger according to your information. Even if I change the number to catch ERROR, INFORMATION or WARNING, I see no changes in zabbix reporting.

                              Trigger :
                              Code:
                              {srv-vcm1:eventlog[Application].logseverity(0)}=1
                              Item :
                              Code:
                              eventlog[application]
                              How can I generate more logs ? (I've tried to change the parameter DebugLevel on zabbix agent, but no usable information is shown about event logs).

                              Thank everyone for your answers.

                              Comment

                              Working...