Submit a ticketCall us

Get a crash course on Network Monitoring delivered right to your inbox
This free 7-day email course provides a primer to the philosophy, theory, and fundamental concepts involved in IT monitoring. Lessons will explain not only how to perform various monitoring tasks, but why and when you should use them. Sign up now.

Home > Success Center > Network Performance Monitor (NPM) > Syslog rule actions to send an email and write to the Windows Event log

Syslog rule actions to send an email and write to the Windows Event log

Table of contents

Updated May 22, 2017

Overview

This article provides steps to use the following syslog rule actions:

  • Send an Email: an action where an email is sent when the defined rule in syslog is triggered
  • Write to Windows Event log: an action where an event is written to the Windows Event log in the Orion server or on a remote Windows server

Environment

All Orion Platform products

Steps

  1. On the Orion server, launch the  Syslog Viewer.
  2. In this example, a rule is created to send an email and write to the Orion server's Windows Event log when the Orion syslog receives a syslog message from any source that contains Licensing Server.

     
  3. From the Syslog Viewer, click .
  4. Click Add New Rule.
  5. Assign a rule name.
  6. In Source IP Address, enter * so the rule applies to any source that forwards syslog to Orion. Otherwise, specify an IP address or IP address range.
  7. Leave the DNS Hostname Pattern field as is or specify a DNS host name pattern.
  8. In the Message tab, enter * in the Message Type Pattern field. 
  9. In the Syslog Message Pattern enter *Licensing Server* for this rule to apply to any syslog message that contains Licensing Server.
  10. In the Severity/Facility tab, select Warning under Message Severity because the particular syslog message that contains Licensing Server has a Warning severity.
  11. Leave the Time of Day and Trigger Threshold tabs as is.
  12. Under Alert Actions, set the following actions:
    • Send an E-mail/Page
      1. In the Alert Actions tab, click Add New Action and select Send an E-mail/Page.
      2. Under E-mail/Page Addresses, enter the recipient's email address.

        The Message tab contains default variables to display the time, message type, and the syslog message.
      3. In the SMTP Server tab, enter the IP address of your mail server.
      4. Click OK to save the email action.
    • Write to Orion server Windows Event Log
      1. In the Actions tab, click Add New Action and select Windows Event Log.
      2. Select Log Message in Event Log on NetPerfMon Server. The event will be written in the Windows Event log for Windows and not in the event for the Orion Web Console.
      3. Click OK to save the action.
  13. Click OK to save the rule. The new rule shows up in the list of rules.

 

The following are sample results of both actions:

  • Email about a syslog message that contains Licensing Server:
  • Windows Event Viewer on the server where Orion is installed and running:

 

 

 

Last modified
16:51, 21 May 2017

Tags

Classifications

Public