Ad Widget

Collapse

Log monitoring and alerting solution on zabbix ?

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • Mat1
    Junior Member
    • Oct 2024
    • 2

    #1

    Log monitoring and alerting solution on zabbix ?

    Hello everyone,

    I discovered zabbix not too long ago, I am currently looking for a solution to alert and monitor logs from several servers and also to monitor the log centralization server. By browsing the forum and the different posts, I find solutions that are not updated or do not work. This is why today I come here to find out if anyone has any knowledge in this area and if they can help me.

    My zabbix server is currently running version 5.0. I am afraid of having compatibility problems in setting up an IT solution for alerting and monitoring logs.

    Any help is welcome, and I thank you in advance for the attention you will post to this topic.

    Sincerely,
    Mat1
  • tim.mooney
    Senior Member
    • Dec 2012
    • 1427

    #2
    There's a section specifically on log file monitoring in the documentation: https://www.zabbix.com/documentation...ypes/log_items

    As covered in that documentation, your agent and server must be configured for "Active" mode.

    Comment

    • Mat1
      Junior Member
      • Oct 2024
      • 2

      #3
      Thank you for your response, I managed to retrieve the logs on the zabbix web interface, now I am looking for how to be alerted by email when an error is reported in my log.

      I'm also looking to see if there are already templates for displaying errors in the logs like a graph or something else.

      Comment

      • cyber
        Senior Member
        Zabbix Certified SpecialistZabbix Certified Professional
        • Dec 2006
        • 4806

        #4
        Logs are usually too specific to have out-of-the-box templates...
        The way Zabbix does log monitoring is a bit tricky. You need to find a balance between having too general patterns to find (ie few items) and load of triggers and trying to maintain their statuses (problem vs Ok as item value can change often which recalculates all related triggers) or having many precice patterns (which may have impact on agent side, as same file is parsed for many things separately) and simple triggers.. It works best on logs that are short and have only required information, like something started and something finished etc.. Counting matches also... But it all works line-by-line, so you cannot pull a trace out of a log etc..

        Comment

        Working...