Ad Widget

Collapse

Eventlog and no match in certain strings..

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • sege
    Member
    • Jan 2008
    • 40

    #1

    Eventlog and no match in certain strings..

    Hello, I'd like to monitor event logs on Windows servers. I'd like to trigger on warning and high events.

    But, I need a way to not trigger on certain strings. For example "31B2F340-016D-11D2-945F-00C04FB984F9" which appear here and there in a High state.

    How to I do this? I have one item:
    eventlog[Application]

    and twp triggers:
    ({Template_Windows:eventlog[Application].nodata(3600)}#1)&({Template_Windows:eventlog[Application].logseverity(4)}=4)
    ({Template_Windows:eventlog[Application].nodata(3600)}#1)&({Template_Windows:eventlog[Application].logseverity(2)}=2)

    I have tried getting some kind of regex to exclude stuff in my item, like
    eventlog[Application,!"string"] and so on without any luck.

    A pointer please?
  • sege
    Member
    • Jan 2008
    • 40

    #2
    No ideas inte this matter?

    Comment

    • trikke
      Senior Member
      • Aug 2007
      • 140

      #3
      Hi sege,

      why don't u use something like

      {Template_Windows:eventlog[Application].str(31B2F340-016D-11D2-945F-00C04FB984F9)}=1 -> means this string was found in last value. Just put this in your trigger statement.

      Greets
      Patrick

      Comment

      • sege
        Member
        • Jan 2008
        • 40

        #4
        Actually I did just that thing yesterday but thanks anyway.

        It'll be a very, very long expression statement though, not sure this is the best way but I can't think of anything else in Zabbix.

        Maybe have the expression box expanded to a few rows or something would be good and have like one expression per row or something instead. Easier to read..

        Comment

        Working...