Logwatch on linux

Hi netanelps,

as logfiles do not have a state that can be monitored, check_mk shows the most worse state in the logfile since the last “clear”. To clear the state of the logwatch-service for a logfile you have to clear the logfile as shown in your screenshot. After this the Check becomes OK again until check_mk finds the next error in the logfile. Thats the way check_mk monitors logfiles. After clearing the logfile, the contents of the logfile is no more available in check_mk. If you want to do this you need a solution like greylog or simliar.

1 Like