Ad Widget

Collapse

Help with creating a trigger on a Windows event log Critical log event

Collapse
This topic has been answered.
X
X
 
  • Time
  • Show
Clear All
new posts
  • greavette
    Member
    • Jul 2015
    • 82

    #1

    Help with creating a trigger on a Windows event log Critical log event

    Hello,

    I'm using Zabbix 6.0 and I've created a simple template that pulls in my Windows System Logs from Event Viewer. The template is working and when Viewing Latest Data the History shows me all events pulled into my Zabbix.

    I would like to create a trigger for any System event that is listed as Critical. I don't have any specific System event but would like to alert on any Critical Event. How would I build my new Trigger in this template provide the dashboard alert I'd like to see.

    Thank you.
  • Answer selected by greavette at 24-10-2022, 03:32.
    cyber
    Senior Member
    Zabbix Certified SpecialistZabbix Certified Professional
    • Dec 2006
    • 4807


    logseverity (/host/key,<#num<:time shift>>)
    Log severity of the last log entry. See common parameters.

    #num (optional) - the Nth most recent value
    Supported value types: log

    Returns:
    0 - default severity
    N - severity (integer, useful for Windows event logs: 1 - Information, 2 - Warning, 4 - Error, 7 - Failure Audit, 8 - Success Audit, 9 - Critical, 10 - Verbose).
    Zabbix takes log severity from Information field of Windows event log.

    Comment

    • cyber
      Senior Member
      Zabbix Certified SpecialistZabbix Certified Professional
      • Dec 2006
      • 4807

      #2

      logseverity (/host/key,<#num<:time shift>>)
      Log severity of the last log entry. See common parameters.

      #num (optional) - the Nth most recent value
      Supported value types: log

      Returns:
      0 - default severity
      N - severity (integer, useful for Windows event logs: 1 - Information, 2 - Warning, 4 - Error, 7 - Failure Audit, 8 - Success Audit, 9 - Critical, 10 - Verbose).
      Zabbix takes log severity from Information field of Windows event log.

      Comment

      • mzeman81
        Junior Member
        • Dec 2020
        • 27

        #3
        Is possible to bind it with 3 or more consecutive Windows failed logons?

        Comment

        Working...