[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Ignoring strings in event logs
- To: xymon (at) xymon.com
- Subject: Ignoring strings in event logs
- From: Colin Coe <colin.coe (at) gmail.com>
- Date: Mon, 4 Oct 2010 12:43:39 +0800
- Dkim-signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:mime-version:received:received:date:message-id :subject:from:to:content-type; bh=eR/pLBvdXYl/Ulb4YM3itrV8Djbp2PLfFM045RQRFRA=; b=Ed11fjKX6bG1csUM8BpKpE8G3fq2zHiLybeoKJvGNK+X+4HxtlHz1+3JF7DOiO1tuM xniuIWpkgvAuG8Dhv4j65NS2sgHLquFsabnXqbuiUoeCBcy1HcRcz2ks74MwQ50PWq03 w28QxG8Binuv0rMAq8+4aYhBkVoQJ4QOOVIaE=
- Domainkey-signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=mime-version:date:message-id:subject:from:to:content-type; b=DS9o8m62AD69Ijj9gUj378/ujsP96/j4Q1yW8sZmcw8Y+ocP43cZVEyUmi4+0+CTlY nVIWzJv/0lUJBKCBz2NKTECPboU3R0/C1hz1k8zXMblqEKg8GnJn23tw17rvv+mdXAJF EitzB/4L4AMOeRU6ZoyhUNwK/clk/9oJHEzsU=
Hi all
I have the following in my hobbit-clients.cfg on the Xymon server
---
CLASS=win32
LOAD 80 90 # Load threholds are in %
PORT "LOCAL=%([.:]20000)$" TEXT=RemotelyAnywhere
LOG %.* %error -.* COLOR=yellow
LOG eventlog:Security %failure.* COLOR=yellow
LOG eventlog:Application %warning.* COLOR=yellow
IGNORE="%(Warning: IIS log failed to write entry|Many client computers
have not reported back|Unsuccessful logon attempt from IP address .*
Secure (SSL) Connection).*"
LOG eventlog:System %error.* COLOR=yellow
---
I'm finding that I'm still getting warnings coming up from the WSUS
server regarding the clients that have not checked.
Could someone advise what I'm doing wrong here?
Thanks
CC
--
RHCE#805007969328369