[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [xymon] Re: Ignoring strings in event logs



Wherever you go, there you are.  

On Oct 4, 2010, at 8:15 PM, Colin Coe <colin.coe (at) gmail.com> wrote:

> Anyone have ideas on this?
> 
> CC
> 
> On Mon, Oct 4, 2010 at 12:43 PM, Colin Coe <colin.coe (at) gmail.com> wrote:
>> Hi all
>> 
>> I have the following in my hobbit-clients.cfg on the Xymon server
>> ---
>> CLASS=win32
>>        LOAD 80 90 # Load threholds are in %
>>        PORT "LOCAL=%([.:]20000)$" TEXT=RemotelyAnywhere
>>        LOG %.*  %error -.* COLOR=yellow
>>        LOG eventlog:Security  %failure.* COLOR=yellow
>>        LOG eventlog:Application  %warning.* COLOR=yellow
>> IGNORE="%(Warning: IIS log failed to write entry|Many client computers
>> have not reported back|Unsuccessful logon attempt from IP address .*
>> Secure (SSL) Connection).*"
>>        LOG eventlog:System %error.* COLOR=yellow
>> ---
>> 
>> I'm finding that I'm still getting warnings coming up from the WSUS
>> server regarding the clients that have not checked.
>> 
>> Could someone advise what I'm doing wrong here?
>> 
>> Thanks
>> 
>> CC
>> 
>> --
>> RHCE#805007969328369
>> 
> 
> 
> 
> -- 
> RHCE#805007969328369
> 
> To unsubscribe from the xymon list, send an e-mail to
> xymon-unsubscribe (at) xymon.com
> 
> 

Try removing the double quotes and replacing each space with a \s (backslash-s). That is what seems to work best for me. 
Steve