Ad Widget

Collapse

Monitoring Windows Event Viewer

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • krcourser
    Junior Member
    • Oct 2009
    • 8

    #1

    Monitoring Windows Event Viewer

    I am just trying to learn a bit about Zabbix and I see entries about monitoring the Event Viewers on Windows Systems but I can't find anything about how to setup to monitor for a specific Event ID. We want to watch for an event if our Trust between our two Domains goes down. In the System Log we get the Type: Error Event ID:5719 shows up with Source NETLOGON in the.

    Does anyone have any samples of this kind of Trigger? Any help will be appreciated.

    krcourser
  • hulting74
    Member
    • Nov 2008
    • 30

    #2
    more information here

    Hi

    Try the Wiki

    http://www.zabbix.com/wiki/howto/mon...ndows_eventlog

    :-)

    /S

    Comment

    • NOB
      Senior Member
      Zabbix Certified Specialist
      • Mar 2007
      • 469

      #3
      Originally posted by hulting74
      Hi hulting74

      the wiki article is fine, but it won't help that much except showing the idea and principle.

      Event-IDs are not support by ZABBIX up to 1.6.x.
      They are supported from 1.7.x on and will appear in 1.8.
      The Event-Id field will be in the DB and triggers can be defined using
      it.
      However, we don't use 1.7.x, yet. So I don't know how to specify the trigger
      exactly.

      We must use the Event-Id now, so we did a patch for it for the
      windows agent as well as for the server.

      Regards,

      Norbert.

      Comment

      • krcourser
        Junior Member
        • Oct 2009
        • 8

        #4
        Monitoring Event Log

        Thanks for the info, we only have version 1.4 and I doubt I can get them to upgrade. Thanks so much for your input.

        I have looked at the wiki a hundred times and it hasn't helped and I just read a thread today that got me 1 step further.

        We now have version 1.8 and I got this to work just today
        {myserver:eventlog[Application].logsource(SceCli)}=1

        But that is looking for a source not an Event ID and when I try either of these it doesn't work, what is the function you use to specify the Event ID? because .logeventid isn't one.

        {myserver:eventlog[Application]eventid(1704)}=1
        ({myserver:eventlog[Application].logsource(SceCli)}=1)&({myserver:eventlog[Application]eventid(1704)}=1)

        I really want to search for a specific Event ID and Source together to make the trigger more specific.
        Last edited by krcourser; 14-04-2010, 22:52. Reason: Update and Reply

        Comment

        Working...