Ad Widget

Collapse

Monitor Windows event logs

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • amitshmil
    Junior Member
    • Nov 2016
    • 3

    #1

    Monitor Windows event logs

    Hi,
    I'm trying to monitor a Windows 2008 Domain controller for specif event id

    I want to to fire alarm when event 13508 occurs on the server but clear the alarm when 13509 occurs (this event says that everything is fine).

    is it possible?
  • alientm
    Member
    • Aug 2014
    • 51

    #2
    For me it works something like this:

    Items:
    Name: PC unlock
    Type: Active
    Key: eventlog[Security,,,,4800|4801]
    Type of information: log

    Triggers:
    Name: Dektop unlock !
    Expression: ({TRIGGER.VALUE}=0 and {PC_NAME:eventlog[Security,,,,4800|4801].logeventid(4801)}=1) or ({TRIGGER.VALUE}=1 and {PC_NAME:eventlog[Security,,,,4800|4801].logeventid(4800)}=0)

    Comment

    • onallion
      Senior Member
      • Mar 2016
      • 131

      #3
      Just trigger when event 13508 occurs, and then use recovery expression to recover only when event 13509 occurs. Easy as pie

      Comment

      • amitshmil
        Junior Member
        • Nov 2016
        • 3

        #4

        Let me try that...

        Comment

        • emz
          Junior Member
          • Mar 2014
          • 20

          #5
          What about the following trigger:

          eventlog[System,,"Error",,^6008$,10,skip].logeventid(^6008$)}=1 and eventlog[System,,"Error",,^6008$,10,skip].nodata(300)}=0

          I face the following issue - if I use nodata(300)}=0, the trigger is not activated at all. If I use nodata(300)}=1, the alarm never disappears (no recovery).
          Can you recommend how to deal with the situation?

          Comment

          • Cpt. Lunchbox
            Junior Member
            • Feb 2019
            • 11

            #6
            emz

            Give this a try:

            Code:
            .nodata(300[B]s[/B])}=0 or .nodata([B]5m[/B])}=0
            Worked for me

            Comment

            • emz
              Junior Member
              • Mar 2014
              • 20

              #7
              Yes, thank you! I get the result I want!

              Comment

              • Mitesh Patel
                Junior Member
                • Jul 2019
                • 1

                #8
                Can you please help me regarding how to windows server event viewer log monitoring in Zabbix server.

                Comment

                Working...