NetXMS Support Forum

Please login or register.

Login with username, password and session length

Author Topic: Alert based on syslog amount  (Read 185 times)

Egert143

  • Newbie
  • *
  • Posts: 40
    • View Profile
Alert based on syslog amount
« on: June 18, 2019, 02:52:16 pm »

Hello

Wanted to ask if its possible to alert based on how much node has logged syslog messages? For example if switch is usualy quiet and then suddenly starts generating alot of logs, is it possible to detect?

Egert
Logged

Victor Kirhenshtein

  • Lead Developer
  • Administrator
  • Hero Member
  • *****
  • Posts: 6797
    • View Profile
Re: Alert based on syslog amount
« Reply #1 on: June 19, 2019, 12:54:15 pm »

Hi,

you can configure DCI on a switch with source "internal" and parameter ReceivedSyslogMessages- it is cumulative counter for received syslog messages. Then you can either do delta transformation and create threshold on it or use "diff" threshold on raw value.

Best regards,
Victor
Logged

Egert143

  • Newbie
  • *
  • Posts: 40
    • View Profile
Re: Alert based on syslog amount
« Reply #2 on: June 19, 2019, 02:38:44 pm »

That was simple solution, thanks :)
Logged