DX Unified Infrastructure Management

  • 1.  Logmon probe exclude rule

    Posted Feb 08, 2017 02:12 AM

    We need to exclude the below alerts from logmon probe but the exclude expression under exclude rule in logmon probe is not working. Please suggest the string to exclude the below alerts.

     

    Alert:- CFRSV50213003AP nss_wins[17912]:   rpc_api_pipe: Remote machine A00DCFROXY01.za.if.atcsg.net

    Key Word:- nss_wins

    Logmon probe version:- 3.56



  • 2.  Re: Logmon probe exclude rule

    Broadcom Employee
    Posted Feb 08, 2017 05:49 AM

    Dear Shubhanker,

     

    just to clarify, you have a logmon profile that successfully generates alarms based on your selection, and one of the alarms messages is based on the alarm snippet you pasted above. This specific alarm message you want to exclude from creating an actual logmon alarm.

     

    Specifically, you are looking at this section:

    https://docops.ca.com/ca-unified-infrastructure-management-probes/ga/en/alphabetical-probe-articles/logmon-log-monitoring/logmon-im-configuration/logmon-advanced-im-configuration#logmonAdvancedIMConfiguration-CreateExcludeRules

     

    The exclude rules works on the same principle as the match on the watcher profile, please refer to this part of the documentation for some hints regarding the creation of the regex:

    https://docops.ca.com/ca-unified-infrastructure-management-probes/ga/en/alphabetical-probe-articles/logmon-log-monitoring/logmon-hints-and-examples

     

    What regex are you using at this moment? Do you need to exclude the specific text above only? Or what are the qualifying parameters for the exclusion? (such as hostname, message  etc)

     

    We would need a bit more information to be able to assist you here. Also worth noting is that the current version  is 5.70, but there were no fixed defects since 3.56 that would apply to exclude rules.

     

    Kind Regards,

     

    Martin Fink

    CA Tech Support



  • 3.  Re: Logmon probe exclude rule

    Broadcom Employee
    Posted Feb 08, 2017 12:20 PM

    I just tried with the steps given in the doc - logmon Advanced AC Configuration - CA Unified Infrastructure Management Probes - CA Technologies Documentation using version 3.70 and it has worked.. 

    Thanks.

    -Sayeed