Anyone have any examples on how to take a " major syslog trap" and parse that out to a custom alert? Right now when I get a major or critical, the generic alert which i cant really do much with.
i get the device name and such but it just falls in a generic bucket.
example:
A MAJOR SYSLOG EVENT HAS OCCURRED
Mar 9, 2018 11:19:02 AM CST
%ENVMON-3-FAN_FAILED: Fan 1 not rotating
alarm title and alarm type both have this: a major syslog event has occurred
alarm details: An unknown syslog message with a severity of 2 or 3 has been received
what i would like to do is to get the syslog and have the title of this one say: < devicex> < ip x.x.xx.> %ENVMON-3-FAN_FAILED: Fan 1 not rotating