Ignoring strings in event logs
Colin Coe
colin.coe at gmail.com
Mon Oct 4 06:43:39 CEST 2010
Hi all
I have the following in my hobbit-clients.cfg on the Xymon server
---
CLASS=win32
LOAD 80 90 # Load threholds are in %
PORT "LOCAL=%([.:]20000)$" TEXT=RemotelyAnywhere
LOG %.* %error -.* COLOR=yellow
LOG eventlog:Security %failure.* COLOR=yellow
LOG eventlog:Application %warning.* COLOR=yellow
IGNORE="%(Warning: IIS log failed to write entry|Many client computers
have not reported back|Unsuccessful logon attempt from IP address .*
Secure (SSL) Connection).*"
LOG eventlog:System %error.* COLOR=yellow
---
I'm finding that I'm still getting warnings coming up from the WSUS
server regarding the clients that have not checked.
Could someone advise what I'm doing wrong here?
Thanks
CC
--
RHCE#805007969328369
More information about the Xymon
mailing list