<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML xmlns="http://www.w3.org/TR/REC-html40" xmlns:v =
"urn:schemas-microsoft-com:vml" xmlns:o =
"urn:schemas-microsoft-com:office:office" xmlns:w =
"urn:schemas-microsoft-com:office:word" xmlns:x =
"urn:schemas-microsoft-com:office:excel" xmlns:p =
"urn:schemas-microsoft-com:office:powerpoint" xmlns:a =
"urn:schemas-microsoft-com:office:access" xmlns:dt =
"uuid:C2F41010-65B3-11d1-A29F-00AA00C14882" xmlns:s =
"uuid:BDC6E3F0-6DA3-11d1-A2A3-00AA00C14882" xmlns:rs =
"urn:schemas-microsoft-com:rowset" xmlns:z = "#RowsetSchema" xmlns:b =
"urn:schemas-microsoft-com:office:publisher" xmlns:ss =
"urn:schemas-microsoft-com:office:spreadsheet" xmlns:c =
"urn:schemas-microsoft-com:office:component:spreadsheet" xmlns:oa =
"urn:schemas-microsoft-com:office:activation" xmlns:html =
"http://www.w3.org/TR/REC-html40" xmlns:q =
"http://schemas.xmlsoap.org/soap/envelope/" XMLNS:D = "DAV:" xmlns:x2 =
"http://schemas.microsoft.com/office/excel/2003/xml" xmlns:ois =
"http://schemas.microsoft.com/sharepoint/soap/ois/" xmlns:dir =
"http://schemas.microsoft.com/sharepoint/soap/directory/" xmlns:ds =
"http://www.w3.org/2000/09/xmldsig#" xmlns:dsp =
"http://schemas.microsoft.com/sharepoint/dsp" xmlns:udc =
"http://schemas.microsoft.com/data/udc" xmlns:xsd =
"http://www.w3.org/2001/XMLSchema" xmlns:sub =
"http://schemas.microsoft.com/sharepoint/soap/2002/1/alerts/" xmlns:ec =
"http://www.w3.org/2001/04/xmlenc#" xmlns:sp =
"http://schemas.microsoft.com/sharepoint/" xmlns:sps =
"http://schemas.microsoft.com/sharepoint/soap/" xmlns:xsi =
"http://www.w3.org/2001/XMLSchema-instance" xmlns:udcxf =
"http://schemas.microsoft.com/data/udc/xmlfile" xmlns:wf =
"http://schemas.microsoft.com/sharepoint/soap/workflow/" xmlns:mver =
"http://schemas.openxmlformats.org/markup-compatibility/2006" xmlns:m =
"http://schemas.microsoft.com/office/2004/12/omml" xmlns:mrels =
"http://schemas.openxmlformats.org/package/2006/relationships" xmlns:ex12t =
"http://schemas.microsoft.com/exchange/services/2006/types" xmlns:ex12m =
"http://schemas.microsoft.com/exchange/services/2006/messages" XMLNS:Z =
"urn:schemas-microsoft-com:"><HEAD><TITLE>Re: [Nagios-users] Monitoring Windows Eventviewer</TITLE>
<META http-equiv=Content-Type content="text/html; charset=us-ascii">
<META content="MSHTML 6.00.2900.3314" name=GENERATOR>
<STYLE>@font-face {
font-family: Cambria Math;
}
@font-face {
font-family: Calibri;
}
@font-face {
font-family: Tahoma;
}
@page Section1 {size: 612.0pt 792.0pt; margin: 72.0pt 72.0pt 72.0pt 72.0pt; }
P.MsoNormal {
FONT-SIZE: 12pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman","serif"
}
LI.MsoNormal {
FONT-SIZE: 12pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman","serif"
}
DIV.MsoNormal {
FONT-SIZE: 12pt; MARGIN: 0cm 0cm 0pt; FONT-FAMILY: "Times New Roman","serif"
}
A:link {
COLOR: blue; TEXT-DECORATION: underline; mso-style-priority: 99
}
SPAN.MsoHyperlink {
COLOR: blue; TEXT-DECORATION: underline; mso-style-priority: 99
}
A:visited {
COLOR: purple; TEXT-DECORATION: underline; mso-style-priority: 99
}
SPAN.MsoHyperlinkFollowed {
COLOR: purple; TEXT-DECORATION: underline; mso-style-priority: 99
}
P {
FONT-SIZE: 12pt; MARGIN-LEFT: 0cm; MARGIN-RIGHT: 0cm; FONT-FAMILY: "Times New Roman","serif"; mso-style-priority: 99; mso-margin-top-alt: auto; mso-margin-bottom-alt: auto
}
SPAN.EmailStyle18 {
COLOR: #1f497d; FONT-FAMILY: "Calibri","sans-serif"; mso-style-type: personal-reply
}
.MsoChpDefault {
FONT-SIZE: 10pt; mso-style-type: export-only
}
DIV.Section1 {
page: Section1
}
</STYLE>
<!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]--></HEAD>
<BODY lang=EN-US vLink=purple link=blue>
<DIV dir=ltr align=left><FONT face=Arial color=#0000ff
size=2></FONT><BR> </DIV>
<DIV></DIV>
<DIV class=Section1>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><SPAN
class=198450814-03062008><FONT face=Arial color=#0000ff
size=2> > </FONT></SPAN>Thanks for the info,<o:p></o:p></SPAN></P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><o:p> </o:p></SPAN></P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><SPAN
class=198450814-03062008><FONT face=Arial color=#0000ff
size=2> > </FONT></SPAN>Great that it can be done with the
NSClient++ as I have it installed on all our servers.<o:p></o:p></SPAN></P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><o:p> </o:p></SPAN></P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><SPAN
class=198450814-03062008><FONT face=Arial color=#0000ff
size=2> > </FONT></SPAN>What do I need to define in the NSClient++
agent and where ?<o:p></o:p></SPAN></P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><SPAN
class=198450814-03062008><FONT face=Arial color=#0000ff
size=2> > </FONT></SPAN>Is it in the .ini file or elsewhere ?<SPAN
class=198450814-03062008><FONT face=Arial color=#0000ff
size=2> </FONT></SPAN></SPAN></P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><SPAN
class=198450814-03062008></SPAN></SPAN> </P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><SPAN
class=198450814-03062008><FONT face=Arial color=#0000ff size=2>The only thing
you need to do on the Windows server is enable the CheckEventLog.dll by removing
the semicolon from that line in the nsc.ini file.</FONT></SPAN></SPAN></P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><SPAN
class=198450814-03062008><FONT face=Arial color=#0000ff
size=2></FONT></SPAN></SPAN> </P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><SPAN
class=198450814-03062008><FONT face=Arial color=#0000ff
size=2>Regards, </FONT></SPAN></SPAN></P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><SPAN
class=198450814-03062008><FONT face=Arial color=#0000ff
size=2></FONT></SPAN></SPAN> </P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><SPAN
class=198450814-03062008><FONT face=Arial color=#0000ff size=2>-greg
</FONT></SPAN></SPAN><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><o:p></o:p></SPAN></P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><o:p></o:p></SPAN> </P>
<P class=MsoNormal><SPAN
style="FONT-SIZE: 11pt; COLOR: #1f497d; FONT-FAMILY: 'Calibri','sans-serif'"><o:p> </o:p></SPAN></P>
<DIV>
<DIV
style="BORDER-RIGHT: medium none; PADDING-RIGHT: 0cm; BORDER-TOP: #b5c4df 1pt solid; PADDING-LEFT: 0cm; PADDING-BOTTOM: 0cm; BORDER-LEFT: medium none; PADDING-TOP: 3pt; BORDER-BOTTOM: medium none">
<P class=MsoNormal><B><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'">From:</SPAN></B><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Tahoma','sans-serif'"> Frater, Greg J
[mailto:GJFRATER@bechtel.com] <BR><B>Sent:</B> maandag 2 juni 2008
21:41<BR><B>To:</B> Tim Van Caeyzeele<BR><B>Cc:</B>
nagios-users@lists.sourceforge.net<BR><B>Subject:</B> Re: [Nagios-users]
Monitoring Windows Eventviewer<o:p></o:p></SPAN></P></DIV></DIV>
<P class=MsoNormal><o:p> </o:p></P>
<P><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">>Dear
All,</SPAN> <o:p></o:p></P>
<P><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">>Would anyone
have experience in checking the windows eventviewer for certain events, or
turning nagios red in case of ERRORs ?</SPAN><o:p></o:p></P>
<P><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">>What script are
you using ? preferably something that can simply interact with NSClient</SPAN>
<o:p></o:p></P>
<P><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">We do this using
the NSClient++ agent (</SPAN><A href="file:///\\www.nsclient.org"><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">www.nsclient.org</SPAN></A><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">). It checks the event
logs and filters them based on criteria you define, alerting when the number of
hits you specify is reached (i.e. when the system log has 1 or more events with
an ID of XXXX within the last 10 minutes send alerts). Here is an example
we use to monitor for a specific Oracle error. In the example we check the
"application" log of the server every "60" minutes for events with an ID of "20"
with event type of "Error" containing a string in the text of the message "Can
not allocate log", check turns critical after 1 matching event is found that is
time stamped within the last "65" minutes.</SPAN><o:p></o:p></P>
<P class=MsoNormal><o:p> </o:p></P>
<P><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">Checkcommands.cfg:</SPAN>
<BR><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">define
command{</SPAN> <BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">
command_name check_eventlogs</SPAN> <BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">
command_line $USER1$/check_nrpe -H $HOSTADDRESS$ -p 5666 -c
checkEventLog -a filter=new $ARG1$ MaxWarn=$ARG2$ MaxCrit=$ARG3$
filter-generated=\$ARG4$ $ARG5$ truncate=$ARG6$</SPAN><o:p></o:p></P>
<P><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"># Desc:</SPAN>
<BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">#
$ARG1$ = event logs to check (i.e. file=system file=application)</SPAN>
<BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">#
$ARG2$ = Warning level (i.e. number of hits to generate a warning
response)</SPAN> <BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">#
$ARG3$ = Critical level (i.e. number of hits to generate a critcal
response)</SPAN> <BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">#
$ARG4$ = Time period (i.e. 1 day is '1d' 30 hours is '>30h')</SPAN> <BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">#
$ARG5$ = Filters (i.e. filter-eventID==9009 filter-eventSource=Tcpip) see
</SPAN><A
href="http://www.nsclient.org/nscp/wiki/CheckEventLog/CheckEventLog"><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">http://www.nsclient.org/nscp/wiki/CheckEventLog/CheckEventLog</SPAN></A><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'"> for detailed
info</SPAN><o:p></o:p></P>
<P><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">#
$ARG6$ = Amount of data to return in characters (i.e. truncate=150)</SPAN>
<BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">#
Example: check_nrpe -H server_name_here -p 5666 -c checkEventLog -a filter=new
file=system MaxWarn=1 MaxCrit=1 filter-generated=\>30h filter+eventID==10002
descriptions truncate=138</SPAN><o:p></o:p></P>
<P><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">
}</SPAN> <o:p></o:p></P>
<P><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">Services.cfg:</SPAN>
<BR><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">define
service{</SPAN> <BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">
use
standard-srv</SPAN> <BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">
service_description
eventlog: Oracle archive log errors</SPAN> <BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">
check_command
check_eventlogs!file=application!1!1!>65m!filter+eventID==20
filter+eventType==error filter+message=substr:"Can not allocate
log"!100</SPAN><o:p></o:p></P>
<P><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">
normal_check_interval
60</SPAN> <BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">
notification_options
w,c</SPAN> <BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">
contact_groups
apps</SPAN> <BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">
host_name
server1, server2</SPAN> <BR><SPAN
style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">
}</SPAN> <o:p></o:p></P>
<P><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">HTH,
</SPAN><o:p></o:p></P>
<P><SPAN style="FONT-SIZE: 10pt; FONT-FAMILY: 'Courier New'">-greg</SPAN>
<o:p></o:p></P>
<P class=MsoNormal
style="MARGIN-BOTTOM: 12pt"><o:p> </o:p></P></DIV></BODY></HTML>