Re: OM Logfile encapsulator multiple matched lines (479 Views)
Reply
Advisor
Robert Sorenson
Posts: 41
Registered: ‎02-08-2010
Message 1 of 3 (485 Views)

OM Logfile encapsulator multiple matched lines

I have a logfile that is read every 2 minutes and may have many matches for a poll cycle. In the event I need to show the matched value plus the text of the log entry. the way I define it causes every entry to be looked as unique and it creates many events for each poll cycle. Is there a way to match only on the field causing 1 event and many duplicates with each duplicate entry containing the "unique" LogTime and LogMessage. Hopefully not confusing. this is the text of the logile policy:
IF Condition (Log file line: <*.System><_><*.SubSystem> F <*.LogTime>- <*.LogMessage>)
Honored Contributor
Larry Klasmier
Posts: 891
Registered: ‎06-01-2009
Message 2 of 3 (485 Views)

Re: OM Logfile encapsulator multiple matched lines

Are you suppressing duplicate messages? If so use message correlation and make the message key the text of the message. In the browser you see that message and the duplicate column will indicate how many duplicates.
Occasional Contributor
Senir Christian
Posts: 10
Registered: ‎06-03-2009
Message 3 of 3 (479 Views)

Re: OM Logfile encapsulator multiple matched lines

Duplicate message suppression is great for things like CPU or Disk type policies, but what we've seen is that if a log entry has any kind of difference from one entry to the next, it does not get treated as a duplicate message and is a seperate event.

 

We are also looking for a way to throttle this kind of log spam as some of these lead to emails via fwdemailasmsg.

The opinions expressed above are the personal opinions of the authors, not of HP. By using this site, you accept the Terms of Use and Rules of Participation.