Ad Widget

Collapse

Monitoring Logs: Source and Severity

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • manfro
    Junior Member
    • Jun 2006
    • 25

    #1

    Monitoring Logs: Source and Severity

    Hello,
    I'm monitoring some logs from a CentOs system using the active agentd and a self formatted log of this kind:

    07/08/2007-10:07:01 Application Severity: NIC Link is Down

    Date format is correctly matched with the one I set in the Item date format.
    When I check the latest value I see that localtime column is correctly filled up. Is there a way to format my log in order to make zabbix recognize also Source and Severity data ?

    Thanks

    Zabbix ver. 1.1.7
  • cstackpole
    Senior Member
    Zabbix Certified Specialist
    • Oct 2006
    • 225

    #2
    Bump.

    I have a similar problem. The log file being generated is:
    yyyy-mm-dd hh:MM:ss.lll Severity [Identifier] - Status: Message
    So the History page shows:
    [yyyy-mm-dd hh:MM:ss] yyyy-mm-dd hh:MM:ss - Not classified yyyy-mm-dd hh:MM:ss.lll Severity [Identifier] - Status: Message

    I have the date being read into zabbix just fine. What I am trying to get is all of the fields logged in Zabbix. The severity can be Info|Warn|CRIT|log and on CRIT's I can have a Status of Alert or ERROR that I am currently sending alerts off of based on string parsing. Any help getting the severities to match up would be great.

    It is also kind of frustrating searching through the forums for this type of information when the search function filters out "log" and its variations.

    EDIT:
    I also have noticed that for some reason time stamps that are right on the minute mark do not get their time posted in the 'history' 'local time' field.
    15:15:01.415 gets a time stamp of 15:15:01
    but
    15:15:00.413 gets nothing in its time stamp.
    That is the same for any time value of hh:MM:00.lll
    Any ideas?

    Thanks Guys!
    cstackpole
    Last edited by cstackpole; 06-07-2007, 22:00.

    Comment

    • rrr
      Senior Member
      • Sep 2007
      • 100

      #3
      This problem still exists in ZABBIX 1.6!

      How to put the source & severity field which are logged into zabbix?

      Comment

      • cjwallace
        Senior Member
        • Sep 2008
        • 126

        #4
        Not to hijack this thread and do hope its the same kind of problem.

        I have the same sort of issue. My Time Stamp is always bang on the money but the local time can be seconds \ minutes or even 12 hours out.

        Its really something that is stopping me progress with Zabbix

        Craig

        Comment

        • rrr
          Senior Member
          • Sep 2007
          • 100

          #5
          And what about the source & severity fields? Did your zabbix-installation inserts them correctly?

          Comment

          • cjwallace
            Senior Member
            • Sep 2008
            • 126

            #6
            Well at the moment i only monitor the security logs on my windows domain controllers but no the source and the severity is never filled in at all.

            huuuuuum now that i think about it would seem i have the same problem as you.

            I would really like to see this issue fixed.

            Craig

            Comment

            Working...