<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=us-ascii">
<META content="MSHTML 6.00.2800.1400" name=GENERATOR></HEAD>
<BODY>
<DIV><SPAN class=114335921-02032004><FONT face=Arial color=#0000ff size=2>Hi
Rudy, </FONT>
<P><FONT face=Arial><FONT color=#0000ff><FONT size=2>Assuming that the events
you want to monitor are logged in the Event Log(for your Windows boxes), you
could centralise yor Windows event logs using<SPAN class=114335921-02032004>
</SPAN>Eventlog to Syslog Utility from</FONT></FONT></FONT></P>
<P><FONT face=Arial><FONT color=#0000ff><A
href="https://engineering.purdue.edu/ECN/Resources/Documents/UNIX/evtsys/"><FONT
size=2>https://engineering.purdue.edu/ECN/Resources/Documents/UNIX/evtsys/</FONT></A></FONT></FONT></P>
<P><FONT face=Arial color=#0000ff size=2>and the logsurfer plugin
from</FONT></P>
<P><FONT face=Arial color=#0000ff
size=2>http://naplax.sourceforge.net/check_logsurfer.html</FONT></P>
<P><FONT face=Arial color=#0000ff size=2>in conjunction with logsurfer from
</FONT></P>
<P><FONT face=Arial color=#0000ff
size=2>http://www.cert.dfn.de/eng/logsurf/</FONT></P>
<P><FONT face=Arial><FONT color=#0000ff><FONT size=2>These 3 utils are easy to
setup and make the task of monitoring Windows<SPAN class=114335921-02032004>
</SPAN>Event Logs much simpler.<SPAN class=114335921-02032004> The
check_logsurfer plugin allows you to specify regular expressions to check for,
so you can tune the plugin to respond to a particlar event log
message.</SPAN></FONT></FONT></FONT></P>
<P><SPAN class=114335921-02032004><FONT face=Arial color=#0000ff size=2>Pushing
your logs out to a central Linux box is a better solution - you can analyse the
logs more easily using perl or whatever.</FONT></SPAN></P>
<P><SPAN class=114335921-02032004><FONT face=Arial color=#0000ff size=2>Peter
Edmonds</FONT></SPAN></P></SPAN></DIV>
<DIV><SPAN class=114335921-02032004><FONT face=Arial color=#0000ff
size=2></FONT></SPAN> </DIV>
<DIV><SPAN class=114335921-02032004></SPAN> </DIV>
<DIV><SPAN class=114335921-02032004><FONT face=Arial color=#0000ff
size=2></FONT></SPAN> </DIV>
<DIV><SPAN class=114335921-02032004></SPAN> </DIV>
<BLOCKQUOTE dir=ltr
style="PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #0000ff 2px solid; MARGIN-RIGHT: 0px">
<DIV class=OutlookMessageHeader dir=ltr align=left><FONT face=Tahoma
size=2>-----Original Message-----<BR><B>From:</B>
nagios-users-admin@lists.sourceforge.net
[mailto:nagios-users-admin@lists.sourceforge.net]<B>On Behalf Of </B>Darren
Harrison<BR><B>Sent:</B> Wednesday, March 03, 2004 7:48 AM<BR><B>To:</B> Rudy
Montemayor<BR><B>Cc:</B> nagios-users@lists.sourceforge.net<BR><B>Subject:</B>
[Nagios-users] Re: Window event viewer<BR><BR></FONT></DIV><BR><FONT
face=sans-serif size=2>Hi Rudy,</FONT> <BR><FONT face=sans-serif size=2>The
agent seems to keep track of when it last reported the error, so it should
only respond to errors that are new since the agent was last called.
Unfortunately this gets reset when the computer is restarted.</FONT> <BR><FONT
face=sans-serif size=2>The one thing you are probably looking for is that the
service needs to be set to be volatile. Then the error gets reset on the next
call.</FONT> <BR><BR><FONT face=sans-serif size=2>I'm sorry I can't help you
with your last issue, I haven't had this happen a lot.</FONT> <BR><BR><FONT
face=sans-serif size=2>Darren.</FONT> <BR><BR><FONT size=2><TT>"Rudy
Montemayor" <RMontemayor@huntoil.com> wrote on 03/03/2004 09:04:39
a.m.:<BR><BR>> Darren,</TT></FONT> <BR><FONT size=2><TT>>
</TT></FONT> <BR><FONT size=2><TT>> Thanks for the information. I was
able to install the agent on 2 Win<BR>> systems; however I have some
questions and welcome anybody that can <BR>> help me out.</TT></FONT>
<BR><FONT size=2><TT>> </TT></FONT> <BR><FONT size=2><TT>>
</TT></FONT> <BR><FONT size=2><TT>> 1) What do this agent do exactly?
From what I can tell of the <BR>> operation, it seems that It looks at the
whole log and lets you know<BR>> how many errors there are and when the
last one occurred. Then it <BR>> may be "EventLog OK" and then back to
reporting the errors again. It<BR>> doesn't keep track of what errors it
already reported on; it's <BR>> basically all or nothing.</TT></FONT>
<BR><FONT size=2><TT>> </TT></FONT> <BR><FONT size=2><TT>> 2) I
asked the Windows folks here about the logs and they mentioned <BR>> that
they just let the log roll-over. So that means that once there <BR>> is an
error the agent will continue to flag that error until that <BR>>
particular entry is rolled-over or one manually clears the log; <BR>> which
is the behavior that I'm seeing now.</TT></FONT> <BR><FONT size=2><TT>>
</TT></FONT> <BR><FONT size=2><TT>> 3) There also appears to be some
problem with "(Service Check Timed <BR>> Out)" and I do not know why this
is happening.</TT></FONT> <BR><FONT size=2><TT>> </TT></FONT>
<BR><FONT size=2><TT>> Any help with be appreciated.</TT></FONT> <BR><FONT
size=2><TT>> </TT></FONT> <BR><FONT size=2><TT>> Rudy</TT></FONT>
<BR>
<P><FONT face=Arial size=2>
<HR>
</FONT>
<P></P>
<P><FONT face=Arial size=2>This e-mail is confidential and may contain
information subject to legal privilege. If you are not the intended
recipient please advise us of our error by return e-mail then delete this
e-mail and any attached files. You may not copy, disclose or use the
contents in any way. </FONT></P>
<P><FONT face=Arial size=2>The views expressed in this e-mail may not be those
of Gallagher Group Ltd or subsidiary companies thereof.</FONT> </P>
<P><FONT face=Arial size=2></FONT></P><FONT face=Arial size=2>
<HR>
</FONT>
<P></P></BLOCKQUOTE></BODY></HTML>