Ad Widget

Collapse

Windows Event Logs

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • cm2000
    Junior Member
    • Mar 2009
    • 29

    #1

    Windows Event Logs

    Hi,

    Running zabbix 1.6.6.

    I'm trying to monitor the eventlog of a couple of specific servers, for anything that is a high severity.
    Ideally i'd like it to raise a trigger if we get 3 or 4 high severities within 1 hour (or something like that), and only if it happens within certain time periods.

    In psudo code, I'm looking for:
    Code:
    If time is > 5am, and < 11pm, then
            If I get X events in the past Y minutes, with Z severity, then raise this trigger
    end if

    I have the following statements, but unsure how to plug them all together! So far, i can raise a trigger on a single event, or an event with a specific string in (as that will be next)...

    Code:
    ({T_CM2K_EventViewer:eventlog[application].logseverity(4)}=4)&
    ({T_CM2K_EventViewer:eventlog[application].count(#3)})
    and also this code does my timing -

    Code:
    ({T_CM2K_EventViewer:status.time(0)}>050000)&
    ({T_CM2K_EventViewer:status.time(0)}<230000)

    Can anyone point me in the direction?
  • ad@kbc-clearing.com
    Member
    • Sep 2005
    • 77

    #2
    Logseverity can only be used to check the severity of the last log entry.
    You want to check the severity of a number of log entries.

    E.g. regexp(test,60) gives the number of messages containing "test" in the last 60 secs.
    Unfortunately, the time/count argument is not yet available for logseverity.
    It might be implemented in a future release ......

    I think this would be a nice feature.

    Comment

    • cm2000
      Junior Member
      • Mar 2009
      • 29

      #3
      thanks for the reply!

      OK, understood about the logseverity.. that is a shame....

      but what about this....

      can i check a number of events in the past x seconds that have a source that contains "SMS Agent" or "IDC Agent" or "Email Agent" etc?

      I think i'll know what the sources will be, and if i can check if any quantity come in then that'll be as useful. Unfortunately the description of the event will change each time as it displays the erroring code\procedure\class.

      Comment

      • cm2000
        Junior Member
        • Mar 2009
        • 29

        #4
        *bump*

        Any clues? this forum is full of experts and guru's.. surely somebody most have an idea! (and hopefully flatterly will get me everywhere)
        Last edited by cm2000; 02-02-2010, 13:00. Reason: spelling mistake

        Comment

        Working...