ich steh gerade etwas auf dem Schlauch. Ich möchte eintreffende Syslog-Meldungen in der Eventconsole “sehen”. In der config ist syslog aktiv (omd config ).
Die Meldung kommt am CMK-Server an (TCPDUMP):
Taucht dann aber in der Eventconsole nicht auf.
Ok, so if you did nothing on the webUI side, then please go to Setup → Event Console and add a rule. Just one rule to catch all messages, or you can filter to all warning, or critical messages, pre-tagged from your system.
It’s closed system so I cant place the command on the sending system.
But the tcpdump output in the first post is a incoming syslog message from the sending system captured on the monitoring server.
Can the format of the message somehow be wrong?
My idea was, that the sending system does not send the messages via UDP, or something else is missconfigured. Can you trigger a syslog message in the sending system?
Checkmk should listen on 0.0.0.0:514 which you can check with ‘netstat -plun |grep 514’.
The fact, that you receive the packages in your tcpdump tells me, that the network part works well und the error should be on the way from local interface to web UI.
Can you please control /omd/sites/$SITE/var/log/mkeventd.log and /ome/sites/$SITE/var/mkeventd/history/*.log
This topic was automatically closed 365 days after the last reply. New replies are no longer allowed. Contact an admin if you think this should be re-opened.