Submit a ticketCall us

Get a crash course on Network Monitoring delivered right to your inbox
This free 7-day email course provides a primer to the philosophy, theory, and fundamental concepts involved in IT monitoring. Lessons will explain not only how to perform various monitoring tasks, but why and when you should use them. Sign up now.

Home > Success Center > Log & Event Manager (LEM) > LEM filter does not trigger with User Defined Group condition

LEM filter does not trigger with User Defined Group condition

 

Overview

Attempting to create a filter, where a User-Defined Group is used.

For example, UserLogOff.DetectionIP = GroupTest

Where Group Test has a list of computer names to compare in the condition.

However, no events appear in the new filter.

Environment

LEM 6.3.1

Cause 

If the symbol * is missing, then the condition in the filter will not work.

Resolution

  1. As a test, create a filter that has only one of the servernames within the condition.

    Example: UserLogOff.DetectionIP = *ComputerA*

    Where ComputerA is one of the names that is in the User-Defined Group: GroupTest

    Make sure that this condition works.

  2. If the condition works, then check the column DATA in the User-Defined Group. In this case the GroupTest may only have in the data section: ComputerA. Which is not correct. The data portion should have: *ComputerA*     
  3. Edit the entries in the User-Defined Group, and add the * symbol before and after your data parameters.
  4. Save the changes to your group, and then check on the filter again. User should see that the events have started coming in.

 

Last modified
16:30, 7 Mar 2017

Tags

Classifications

Public