Ad Widget

Collapse

Z6 pre-processing Win Eventlog items now missing Localtime, Source, Severity, EventID

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • seanwasere
    Junior Member
    • May 2012
    • 12

    #1

    Z6 pre-processing Win Eventlog items now missing Localtime, Source, Severity, EventID

    Zabbix 6 pre-processing Windows Eventlog items now losing metadata such as Localtime, Source, Severity, EventID.

    Zabbix 5 didn't lose this information. I'm wondering if there is a new setting somewhere in Z6 to keep this useful information.

    In both images below, hosts are monitored by proxy.
    They are from Z5 LTS and Z6 LTS and have identical item configurations.

    Item
    - type : Zabbix agent (Active)
    - key : eventlog[Security,,,,4625,,skip]
    - type of info : log

    Preprocessing step :
    - name : Regular expression
    - pattern : Account Name:\t\t(.*)
    - output : \0

    Image of Zabbix 5 latest data page before and after applying pre-processing rule to keep 1st line only of event log.
    Click image for larger version  Name:	z5-preprocessing.jpg Views:	0 Size:	60.1 KB ID:	441750

    Image of Zabbix 6 latest data page before and after applying pre-processing rule to keep 1st line only of event log.
    Local time, Source, Severity, Event ID are now missing.

    Click image for larger version  Name:	z6-preprocessing.jpg Views:	0 Size:	61.4 KB ID:	441751

    Last edited by seanwasere; 20-03-2022, 15:21.
Working...