LinuxQuestions.org
Help answer threads with 0 replies.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Server
User Name
Password
Linux - Server This forum is for the discussion of Linux Software used in a server related context.

Notices


Reply
  Search this Thread
Old 08-27-2014, 10:40 AM   #1
dyto
Member
 
Registered: Mar 2014
Posts: 86

Rep: Reputation: Disabled
zabbix log monitoring


hello all
I am monitoring log file with zabbix-agent. for example when it reads from log "SELinux is preventing" it generates alarm by trigger. my questions is that if I set item's update on 1 sec, even in one second it is generating alarm on last match in the log file. I think agent is reading from the bottom of file. how can I generate alarm for each mach by timestamp? any ideas?
 
Old 08-27-2014, 02:12 PM   #2
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
Quote:
Originally Posted by dyto View Post
hello all
I am monitoring log file with zabbix-agent. for example when it reads from log "SELinux is preventing" it generates alarm by trigger. my questions is that if I set item's update on 1 sec, even in one second it is generating alarm on last match in the log file. I think agent is reading from the bottom of file. how can I generate alarm for each mach by timestamp? any ideas?
show us your zabbix_agentd.conf and the script you are using to monitor the log.
And a sanitized snippet of the monitored log please that includes the timestamp.

Do NOT use 1s to update, it's a recipe for failure.

I did something like this for varnish 503 errors with a UTC Timestamp.
solution at https://www.zabbix.com/forum/showpos...89&postcount=9
 
Old 08-27-2014, 02:22 PM   #3
dyto
Member
 
Registered: Mar 2014
Posts: 86

Original Poster
Rep: Reputation: Disabled
ok thanks for you reply.I will show it later now I am not at place. zabbix-agend.conf contains usual settings server ip and hostname of monitored server. I just want to see alert from /var/log/maillog everytime it logs "Virus Detected" if it is logged 10 times logged zabbix gives alert for tenth not for each entry. I want alert for each entry. zabbis server is checking it every 10 minute but there may be 100 entries anyway I have to look logs for investigation but in case of monitoring system I need every entry.
 
Old 08-28-2014, 08:48 AM   #4
Habitual
LQ Veteran
 
Registered: Jan 2011
Location: Abingdon, VA
Distribution: Catalina
Posts: 9,374
Blog Entries: 37

Rep: Reputation: Disabled
You're very welcome.
Let us know how it goes.
 
Old 08-28-2014, 10:31 AM   #5
dyto
Member
 
Registered: Mar 2014
Posts: 86

Original Poster
Rep: Reputation: Disabled
hello again,

here is the my zabbix example how I configured

item:

key: log[/var/log/maillog, Virus Detected,,250]

and the trigger:

Expression: {server.domain:log[/var/log/maillog, Virus Detected,,250].logeventid(1)}=0
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
UPS Monitoring without SNMP (apcupsd > zabbix) - Need some help fruitwerks Linux - Server 6 07-27-2013 08:03 AM
zabbix process monitoring fernfrancis Linux - Newbie 2 06-13-2011 12:32 PM
LXer: Review: Zabbix 1.8 Network Monitoring LXer Syndicated Linux News 0 08-10-2010 07:50 AM
How to add hosts into Zabbix monitoring tool rawand Linux - Software 1 06-03-2010 12:33 AM
LXer: Network Monitoring With Zabbix LXer Syndicated Linux News 0 04-11-2006 06:54 PM

LinuxQuestions.org > Forums > Linux Forums > Linux - Server

All times are GMT -5. The time now is 04:52 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration