D
D
Dexteny2018-07-10 15:25:56
Zabbix
Dexteny, 2018-07-10 15:25:56

How to correctly build a trigger in zabbix based on EventID (from Windows)?

In windows, according to the task, an event with a specific id in the eventlog is created, which is informative in nature, with a specified time for displaying an alert on it. But in Zabbix, 3 alerts appear on it every time, with a difference of about 10 seconds.
I tried different variations of the construction, the result in all cases turned out to be the same.
Trigger expression:

{test_logs:eventlog[Application,,,,^(999|998)$,,].regexp(.)}=1 and
{test_logs:eventlog[Application,,,,^(999|998)$,,].nodata(300)}=0 and
{test_logs:eventlog[Application,,,,^(999|998)$,,].logeventid(999)}=1

And the second. The problem message does not fit completely (on the dashboard), i.e. only 20 characters in the first line followed by "..." . Although, judging by other alerts, it is clear that the length is allowed more than the length inside the window event. If you go to the event, in the "Event details" section, it is also displayed with "...", but in the action messages (to the right of the notification by e-mail) the message is displayed in full.

Answer the question

In order to leave comments, you need to log in

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question