
15
4.
Syslog Monitoring
F u n c t i o ns
When a set keyword is recorded in a syslog ("/var/log/messages"), Syslog Monitoring function reports an
alert to NEC ESMPRO Manager. syslog to be targeted for monitoring is only "/var/log/messages", a
change cannot add it. In addition, the file name after logrotate targeted for monitoring is as follows.
"dateext" is not defined by /etc/logrotate.conf : /var/log/messages.n [n=1, 2, 3 ...]
"dateext" is defined by /etc/logrotate.conf : /var/log/messages-YYYYMMDD
It cannot monitor by Syslog Monitoring function at time except the above file name.
If "compress" is defined by /etc/logrotate.conf, it cannot monitoring by Syslog Monitoring function
because after logrotate file is not text.
With Red Hat Enterprise Linux 6, "dateext" is defined with an existing set price.
With SUSE Linux Enterprise Server, "compress" is defined with an existing set price.
You can add the targeted for monitoring file which does not include "/var/log/messages" character string
one. By the timing of the monitoring interval, chronological order may reverse to check an additional
monitoring file after having checked /var/log/messages.
It becomes only a file output with a format same as a syslog and does not watch the first bank of the
monitoring relevant file.
%b %d %H:%M:%S %HOSTNAME% %MESSAGE%
%b (Jan to Dec) %d (1 to 31) %H (00 to 23):%M (00 to 59):%S (00 to 59) HOSTNAME% %MESSAGE%
In addition, the file name after rotate targeted for additional monitoring is file name .n.
When it appoints the file which logrotate does, in the timing divided by the change of the file name of the log, it
may not watch an additional monitoring relevant file in the latter half part. In the case of
/var/log/vmkernel, it supports a file name after logrotate.
You can add the targeted for monitoring file which does not include "/var/log/messages" character string
one. By the timing of the monitoring interval, chronological order may reverse to check a file monitoring file
after having checked /var/log/messages and an additional monitoring file.
In addition, because it does not support it about a file name after logrotate, in the timing divided by the change
of the file name of the log, it may not watch a file monitoring relevant file in the latter half part.
The format of the file monitoring relevant file does not have the designation.
Syslog Monitoring Event comes by additional / deletion by a new source depending on system environment, a
monitoring event other than a monitoring event registering at the time of NEC ESMPRO Agent installation
beforehand. Refer to chapter 3 "5.Syslog Events Setting" for how to add/delete Syslog Monitoring Event.
S e t t i n g s
From [Syslog Properties] screen, you can set the following information.
To display [Syslog Properties] screen, select "Syslog" on Control Panel (ESMagntconf).
Commenti su questo manuale