We are running 2.92 build 30 on Windows Server 2003 R2 SP2. I'm new to EventSentry (ES) and could use some help.
I've configured a linux server to send syslog entries to ES (into the application log), and I've setup ES to Filter and Email certain log entries. My problem is with the Content Filter.
Here are the 2 logs I'm concerned with in the ES application log:
1) firstname.lastname@example.org[kern/user.notice]: logger: logicaldrive 1 (232.9 GB, RAID 1): OK
2) email@example.com[kern/user.notice]: logger: logicaldrive 2 (1.8 TB, RAID 1): OK
I want ES to send out an error email when the logicaldrives report anything other than OK. This is the exact logic I need:
1) Search for string *logicaldrive*
2) In that same text, search for string *OK*. If you don't find *OK* then trigger an Email Action sending the text in question
You might ask, why don't I just search for FAILED or DEGRADED? The problem is I don't know all of the possible status messages that our RAID controller might spit out to the log. There could be many, so the only way to catch them all is to report any instance where it does not say OK.