Hi All,
We have configured a log monitor on Linux to monitor a log and look for the Expression "ERROR" and trigger an alarm. Also the alarm was supposed to self clear after 10 minutes if no further "ERROR" messages were detected. Below is the monitor and the trigger setup. What is currently happening is the alarm is triggering when ever there is a new expression of any kind added to the log, not just the word "ERROR" . log[/data01/usr/Spectrum/Notifier/test2.log,ERROR] {v00uicaspec01r:log[/data01/usr/Spectrum/Notifier/test2.log,ERROR].nodata(10m)}=0 Can someone tell us what we are missing? TIA
We have configured a log monitor on Linux to monitor a log and look for the Expression "ERROR" and trigger an alarm. Also the alarm was supposed to self clear after 10 minutes if no further "ERROR" messages were detected. Below is the monitor and the trigger setup. What is currently happening is the alarm is triggering when ever there is a new expression of any kind added to the log, not just the word "ERROR" . log[/data01/usr/Spectrum/Notifier/test2.log,ERROR] {v00uicaspec01r:log[/data01/usr/Spectrum/Notifier/test2.log,ERROR].nodata(10m)}=0 Can someone tell us what we are missing? TIA
Comment