Ad Widget

Collapse

Alerting on Trap Strings

Collapse
X
 
  • Time
  • Show
Clear All
new posts
  • denso
    Member
    • Sep 2005
    • 32

    #1

    Alerting on Trap Strings

    is there a way to format a phrase to look for instead of a single word in strings?

    Eaxmple: instead of writing a string that looks for "CIFS: Possible Virus Detected" I have to look for one of the words in the string such as "CIFS" then I would get trigger alerts for all sorts of CIFS messages......
  • Tim S
    Junior Member
    • Jun 2006
    • 13

    #2
    I'm not aware of a way to look for an entire phrase. But I find looking for multiple words just as effective (if less convenient).

    {SNMP_host_obj:snmp_item.str(ActiveX)}=1&{SNMP_hos t_obj:snmp_item.str(detected)}=1

    becomes true if a trap comes through with the text "ActiveX control detected/blocked"

    Just remember not use *any* spaces in the expressions.

    Comment

    • denso
      Member
      • Sep 2005
      • 32

      #3
      sounds pretty good im gonna try this, now if we could get the trigger to switch back to green instead of staying either on or off.

      Comment

      • peter_field
        Member
        • Jun 2006
        • 71

        #4
        Use nodata to have trigger come back off

        See this thread for info on using nodata to get triggers to come back off:


        However, if its getting rid of the ON/OFF problem, then no luck for you, sorry. Maybe in the next release??

        Comment

        Working...