03-07-2014 08:02 AM
With a SiteScope logfile monitor, I would like to receive an alert when there is new errors in the /var/log/messages, excepted if it's related to SSH. In other word, the content match would be something like: " Error message not containing "sshd" and containing "error" "
EXAMPLE of an error message for which I don't want to receive an alert:
Feb 26 19:21:44 host2 sshd: error: PAM: Authentication failure for root from server.mydomain.com
Is there a way to do this ?
Thanks in advance,
03-07-2014 08:10 AM
It will not work for me.
I want to receive an alert each time there is a line containing "error" pattern in /var/log/messages, excepted if the line contains also "sshd".
03-07-2014 10:02 AM
The matched pattern may NOT appear anywhere in content that is being searched. This is a "complement" match, returning an error if the pattern IS found, and succeeding if the pattern is NOT found.
maybe, this modifier fit?
SiteScope Core QA Team Engineer