Ad Widget

Collapse

Zabbix & Syslog-NG

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • aic
    Member
    • Oct 2010
    • 50

    #1

    Zabbix & Syslog-NG

    Hi All,

    Is there any experience merging the advantage of Syslog-NG with Zabbix?

    I am consolidating Syslog-NG log in my Zabbix server (1.8.3) and I am in trouble to show the message in our console.

    This issue is giving me a head-ache.

    Thanks in advance.
    AIC
  • zalex_ua
    Senior Member
    Zabbix Certified Trainer
    Zabbix Certified SpecialistZabbix Certified Professional
    • Oct 2009
    • 1286

    #2
    Originally posted by aic
    Hi All,
    Is there any experience merging the advantage of Syslog-NG with Zabbix?
    Yes. See my pictures in https://support.zabbix.com/browse/ZBXNEXT-470
    This is: UDP -> Syslog-NG -> My own script -(TCP)> Zabbix server.

    I plan to publish someday my script.
    Although there is already a powerful turnkey solution http://www.zabbix.com/forum/showthread.php?t=19180

    Comment

    • aic
      Member
      • Oct 2010
      • 50

      #3
      Error filling the columns with log anlizer.

      Hi All,

      I am trying to catch the error message from my logs and I am completely lost.

      I have the server running the latest version of agent (1.8.3)

      I have configured to run "Zabbix Agent (active)" int zabbix_agentd.conf file.

      I have created an Item to catch and parse this error msg in the file :
      Click image for larger version

Name:	item-error.JPG
Views:	1
Size:	21.7 KB
ID:	309198

      I have set up this action:




      Here I am attaching how I am seeing the "Monitoring" -> "Latest Data" -> "Log Files":

      Click image for larger version

Name:	action-to-catch error in the log.JPG
Views:	1
Size:	43.0 KB
ID:	309199


      Please any suggestions or comments will be welcome.

      Thanks in advance,
      aic
      Attached Files

      Comment

      • aic
        Member
        • Oct 2010
        • 50

        #4
        Zabbix & Syslog-NG

        Thank you so much for yor message zalex_ua.

        I posted here my own configuration. I can see you are getting the right setting into the zabbix console. It is not happen to me now.

        Thanks again.
        aic

        Comment

        • alixen
          Senior Member
          • Apr 2006
          • 474

          #5
          Hi,

          In Zabbix, dependency chain is item -> trigger -> action.
          You have no trigger.
          Check manual for details : http://www.zabbix.com/documentation/...onfig/triggers

          regards,
          Alixen
          http://www.alixen.fr/zabbix.html

          Comment

          • zalex_ua
            Senior Member
            Zabbix Certified Trainer
            Zabbix Certified SpecialistZabbix Certified Professional
            • Oct 2009
            • 1286

            #6
            Firstly, RTFM.

            Originally posted by aic
            I am trying to catch the error message from my logs and I am completely lost.
            I have created an Item to catch and parse this error msg in the file :
            Here I am attaching how I am seeing the "Monitoring" -> "Latest Data" -> "Log
            Files":
            You should use Type of information "Text" instead of "Log". "Log" specially created for windows events logging, not for plain text log. As result you will not see Local time, Source, Severity, Event ID columns.

            Others me presented solution - is not original from Zabbix. Be patience to deal with them. Yes, its have possibility fill all columns for Type of information "Text".

            Originally posted by aic
            I have set up this action:
            Use two condition Trigger value = "OK" and simultaneously Trigger value = "PROBLEM" this is absolutely illogical. I think you should delete condition Trigger value = "OK".

            Comment

            • aic
              Member
              • Oct 2010
              • 50

              #7
              Zabbix & Syslog-NG

              Thanks for the recommendation. The situation improved a litte.

              But, now, as you says, I tried to change in the "Item" -> Type of Information: from "Log" to "Text" and I got this error message trying to save the new configuration:

              "Type of information must be Log for log key"

              Any suggestion?

              Thx

              Comment

              • zalex_ua
                Senior Member
                Zabbix Certified Trainer
                Zabbix Certified SpecialistZabbix Certified Professional
                • Oct 2009
                • 1286

                #8
                oh, yeah, i forgot. this is checking Type of information are fresh future
                No more suggestion, i said all.
                Last edited by zalex_ua; 21-10-2010, 19:18.

                Comment

                • aic
                  Member
                  • Oct 2010
                  • 50

                  #9
                  I really appreciate your help.

                  Now, I am still worried about that...missed, about how to fill in the columns to show the whole message in the "Latest data" view.

                  Because, as the "Severity = Unknown" I can't manage the actions correctly

                  Anyway, thanks for all..at least I am catching and showing the alerts in the console right now ....

                  aic

                  Comment

                  Working...