Ad Widget

Collapse

Eventlog weird behavior

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • antani
    Member
    • Apr 2008
    • 50

    #1

    Eventlog weird behavior

    Items:
    eventlog[Security] <- Get correct data (a list of the occurred events)
    eventlog[System] <- Get correct data

    Triggers:
    {myTemplate:eventlog[Security].logseverity(4)}=4 (Works great)
    {myTemplate:eventlog[System].logseverity(4)}=4 (shows uknown)

    WHY???

    What does the 4 in logseverity(4) means? Which other options are available?
    What does the 4 in =4 means? Which other options are available?

    I read almost everywere but cannot find anything i didn't already try.
    Last edited by antani; 30-04-2008, 17:41.
  • bbrendon
    Senior Member
    • Sep 2005
    • 870

    #2
    Try combing with an &nodata on there.
    Unofficial Zabbix Expert
    Blog, Corporate Site

    Comment

    • trikke
      Senior Member
      • Aug 2007
      • 140

      #3
      Hi Antani,

      From source: eventlog.c

      {
      case EVENTLOG_ERROR_TYPE: *out_severity = 4; break;
      case EVENTLOG_AUDIT_FAILURE: *out_severity = 7; break;
      case EVENTLOG_AUDIT_SUCCESS: *out_severity = 8; break;
      case EVENTLOG_INFORMATION_TYPE: *out_severity = 1; break;
      case EVENTLOG_WARNING_TYPE: *out_severity = 2; break;
      }


      So for your trigger to work u will need a "Error type Eventlog message" to match against!

      There is a smal nifty tool "logevent.exe" which alows u to create Eventlog-Messages from cli.

      Greets
      Patrick

      Comment

      • antani
        Member
        • Apr 2008
        • 50

        #4
        Thanks. It was very useful.

        Comment

        Working...