Network Management

How to set rules for Collection Profiles in Log Analyzer

Step-by-step procedure on how to create rules for created collection profiles.

First published date

2/26/2026 6:38 PM

Last published date

2/26/2026 6:38 PM

Overview

Guide on how to set rules to for created Collection Profiles in Log Analyzer to fire when specific messages have been observed on the monitored log file. 

Product section

Log Analyzer

Resolution

1) Successfully create a Log Collection Profile 

Reference: Create log collection profiles 

2) Go to Log Viewer > Settings > Log Files > My Custom Rules 

3) Create a New Rule and set the name for it.

4) On the Rule Conditions set the following conditions

  • Log Profile is equal to (Name of the Connection Profile that you created)
  • Message contains (phrase or word you'd like to monitor) 

You can also set the following for a more customized rule:

  • Time Window for this rule to be active
  • Entry Count which gives you an option for the rule to fire on every instance or to wait if an x number of instances fires first within a span of time
  • Flood Protection which allows you to stop the rule process for a certain time period before firing again 

5) On the Rule Actions page this is where you can set what are the actions to be taken once the rule conditions are met. 

  • Tag the Entry - allows you to tag the event captured and display it on the Log Viewer page
  • Run an External Program - allows you to run a script on the assigned nodes in your Collection Profile
  • Flag for Discard - will no longer retain the next events where the rule has been triggered to the DB but will still continue to process the rule conditions
  • Stop Processing Rules - once that rule fires for a given log entry, no further log-processing rules are evaluated for that same entry.

6) In addition to the Rule Actions, you can also integrate the SolarWinds Alerts to fire when the conditions are met.

Note: You will need to configure the alert on the Manage Alerts page to set the alert actions (e.g. sending an email to your team or sending a webhook to Teams or Slack)

7) Complete the Wizard and Save the created Log File Rule.