Ad Widget

Collapse

HOWTO: Monitoring Windows Logs?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • misch
    Junior Member
    • Jan 2010
    • 28

    #1

    HOWTO: Monitoring Windows Logs?

    Hi,

    I want to monitor windows logs. From MS I found that there are "Event Types" of "Information", "Warning", "Error", ..."Failure".

    I have an active zabbix agent item eventlog[Application]. Now I want to have a trigger that triggers if Event Type > "Error". In the zabbix doc I found the function logseverity.

    How can I map MS's "Event Type" to logseverity? Just Number 3, so definening a trigger like:
    {MyTemplate::[Application].logseverity(0)}>2

    Thanks for any help.

    Michael.
  • zalex_ua
    Senior Member
    Zabbix Certified Trainer
    Zabbix Certified SpecialistZabbix Certified Professional
    • Oct 2009
    • 1286

    #2
    Originally posted by misch
    I have an active zabbix agent item eventlog[Application]. Now I want to have a trigger that triggers if Event Type > "Error". In the zabbix doc I found the function logseverity.
    hhm, is no error level higher than "Error" . So maybe you want Event Type = "Error" ?

    Originally posted by misch
    How can I map MS's "Event Type" to logseverity? Just Number 3, so definening a trigger like:
    {MyTemplate::[Application].logseverity(0)}>2
    No, for map logseverity to "MS's error" level use:
    Code:
    {MyTemplate::[Application].logseverity(0)}=4
    Logseverity levels:

    1 - information
    2 - warning
    4 - error
    7 - AUDIT_FAILURE
    8 - AUDIT_SUCCESS

    p.s. and in general it is only the beginning , oh when will I finally finish my article for wiki about it ...

    Comment

    • zalex_ua
      Senior Member
      Zabbix Certified Trainer
      Zabbix Certified SpecialistZabbix Certified Professional
      • Oct 2009
      • 1286

      #3
      And which version of you Windows?

      Read this note

      Comment

      Working...