Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
COLLECTD
BUG FIXES
REST CLIENT
IMPROVED WEB UI!
COUNT FIX!
METRICS
Please don’t be angry!
Some times I am busy 
Get over here
and play
NOW!
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Core
Core
Server
Client
Check
Script
Misc
Core
Server
NRPE
NSCA
Client
NRPE
NSCA
Check
System
Eventlog
Script
Python
Lua
Misc Scheduler
Core Server
NRPE
NSCA
Client
NRPE check_remote
NSCA notify_remote
Check
System
check_cpu
check_memory
…
Eventlog Check_eventlog
Script
Python Script Check_???
Lua Script Check_???
Misc Scheduler
Core
Modules …
Settings
ini
reg
https://…
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
foo
bar
key=value
this=that
more this=thattest=test
[/modules]
CheckDisk=enabled
NRPEServer=enabled
[/settings/default]
allowed hosts=127.0.0.1,icinga.org
[/log]
level=debug
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
NRPE
Server
Core
Check
System
Check
EventLog
Check
ExternalScripts
check_foo.bat
QUERY
NRPE
(1024)
QUERY
Port: 5666
allowed hosts
arguments
arguments
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Level Source … …
Error Word … …
Error Excel … …
Info Word … …
Warning Excel … …
Error App1 … …
Warning App1 … …
Error App3 … …
Level Source … …
Error Word … …
Error Excel … …
Info Word … …
Warning Excel … …
Error App1 … …
Warning App1 … …
Error App3 … …
filter=”level=’error’”
Level Source … …
Error Word … …
Error Excel … …
Info Word … …
Warning Excel … …
Error App1 … …
Warning App1 … …
Error App3 … …
filter=”source=’App1’”
Level Source … …
Error Word … …
Error Excel … …
Info Word … …
Warning Excel … …
Error App1 … …
Warning App1 … …
Error App3 … …
filter=”source=’App1’ or source=’App3’”
Level Source … …
Error Word … …
Error Excel … …
Info Word … …
Warning Excel … …
Error App1 … …
Warning App1 … …
Error App3 … …
filter=”source=’App1’ or source=’App3’
or level=’error’”
Level Source … …
Error Word … …
Error Excel … …
Info Word … …
Warning Excel … …
Error App1 … …
Warning App1 … …
Error App3 … …
filter=”source=’App1’ or source=’App3’
or level=’error’ or level=’warning’”
Level Source … …
Error Word … …
Error Excel … …
Info Word … …
Warning Excel … …
Error App1 … …
Warning App1 … …
Error App3 … …
filter=”(source=’App1’ or source=’App3’
or level=’error’ or level=’warning’) and
source!=’Excel’”
filter=”(source in (’App1’,’App3’) or
level in (’error’,’warning’)) and source
!= ’Excel’”
Level Source … …
Error Word … …
Error Excel … …
Info Word … …
Warning Excel … …
Error App1 … …
Warning App1 … …
Error App3 … …
• filter = (id NOT IN ('3', '4', '6', '11', '16', '23', '24', '27', '29', '36', '46', '47',
'50', '56', '134', '142', '219', '267', '270', '1006', '1009', '1014', '1030', '1035',
'1036', '1055', '1058', '1071', '1073', '1085', '1102', '1110', '1111', '1112', '1131',
'1291', '1500', '3095', '5719', '5722', '5783', '5788', '5789', '6008', '7000', '7001',
'7003', '7005', '7009', '7011', '7022', '7023', '7024', '7026', '7030', '7031', '7034',
'7038', '7041', '9015', '9018', '9026', '9028', '10009', '10010', '10016', '10149',
'12294', '15300', '15301', '24679', '36887', '36888', '40960', '40961', '45056') AND
level IN ('error', 'warning')) OR (id IN ('3') AND source NOT IN ('FilterManager') AND
level IN ('error', 'warning')) OR (id IN ('4') AND source NOT IN ('q57','L2ND') AND level
IN ('error', 'warning')) OR (id IN ('6') AND source NOT IN ('Security-Kerberos') AND
level IN ('error', 'warning')) OR (id IN ('11') AND source NOT IN ('Kerberos-Key-
Distribution-Center') AND level IN ('error', 'warning')) OR (id IN ('16') AND source NOT
IN ('WindowsUpdateClient') AND level IN ('error', 'warning')) OR (id IN ('23') AND source
NOT IN ('Eventlog') AND level IN ('error', 'warning')) OR (id IN ('24') AND source NOT IN
('Time-Service') AND level IN ('error', 'warning')) OR (id IN ('27') AND source NOT IN
('Eventlog') AND level IN ('error', 'warning')) OR (id IN ('29') AND source NOT IN
('Kerberos-Key-Distribution-Center') AND level IN ('error', 'warning')) OR (id IN ('36')
AND source NOT IN ('Time-Service') AND level IN ('error', 'warning')) OR (id IN ('46')
AND source NOT IN ('Time-Service') AND level IN ('error', 'warning')) OR (id IN ('47')
AND source NOT IN ('Time-Service') AND level IN ('error', 'warning')) OR (id IN ('50')
AND source NOT IN ('TermDD','Time-Service') AND level IN ('error', 'warning')) OR (id IN
('56') AND source NOT IN ('TermDD') AND level IN ('error', 'warning')) OR (id IN ('134')
AND source NOT IN ('Time-Service') AND level IN ('error', 'warning')) OR (id IN ('142')
AND source NOT IN ('Time-Service') AND level IN ('error', 'warning')) OR (id IN ('219')
AND source NOT IN ('Kernel-pnp') AND level IN ('error', 'warning')) OR (id IN ('267') AND
source NOT IN ('Storage-agents') AND level IN ('error', 'warning')) OR (id IN ('270') AND
source NOT IN ('Storage-agents') AND level IN ('error', 'warning')) OR (id IN ('1006')
AND source NOT IN ('DNS Client Events','GroupPolicy') AND level IN ('error', 'warning'))
OR (id IN ('1009') AND source NOT IN ('picadm') AND level IN ('error', 'warning')) OR (id
IN ('1014') AND source NOT IN ('DNS Client Events') AND level IN ('error', 'warning')) OR
(id IN ('1030') AND source NOT IN ('GroupPolicy') AND level IN ('error', 'warning')) OR
(id IN ('1035') AND source NOT IN ('TerminalServices-RemoteConnectionManager') AND level
IN ('error', 'warning')) OR (id IN ('1036') AND source NOT IN ('TerminalServices-
RemoteConnectionManager') AND level IN ('error', 'warning')) OR (id IN ('1055') AND
source NOT IN ('GroupPolicy') AND level IN ('error', 'warning')) OR (id IN ('1058') AND
source NOT IN ('GroupPolicy') AND level IN ('error', 'warning')) OR (id IN ('1071') AND
source NOT IN ('TerminalServices-RemoteConnectionManager') AND level IN ('error',
'warning')) OR (id IN ('1073') AND source NOT IN ('USER32') AND level IN ('error',
'warning')) OR (id IN ('1085') AND source NOT IN ('GroupPolicy') AND level IN ('error',
'warning')) OR (id IN ('1102') AND source NOT IN ('SNMP') AND level IN ('error',
'warning')) OR (id IN ('1110') AND source NOT IN ('GroupPolicy') AND level IN ('error',
'warning')) OR (id IN ('1111') AND source NOT IN ('Server Agents') AND level IN ('error',
'warning')) OR (id IN ('1112') AND source NOT IN ('GroupPolicy') AND level IN ('error',
'warning')) OR (id IN ('1131') AND source NOT IN ('TerminalServices-
RemoteConnectionManager') AND level IN ('error', 'warning')) OR (id IN ('1291') AND
source NOT IN ('NIC-agents') AND level IN ('error', 'warning')) OR (id IN ('1500') AND
source NOT IN ('SNMP') AND level IN ('error', 'warning')) OR (id IN ('3095') AND source
NOT IN ('Netlogon') AND level IN ('error', 'warning')) OR (id IN ('5719') AND source NOT
IN ('Netlogon') AND level IN ('error', 'warning')) OR (id IN ('5722') AND source NOT IN
('Netlogon') AND level IN ('error', 'warning')) OR (id IN ('5783') AND source NOT IN
('Netlogon') AND level IN ('error', 'warning')) OR (id IN ('5788') AND source NOT IN
('Netlogon') AND level IN ('error', 'warning')) OR (id IN ('5789') AND source NOT IN
('Netlogon') AND level IN ('error', 'warning')) OR (id IN ('6008') AND source NOT IN
('Eventlog') AND level IN ('error', 'warning')) OR (id IN ('7000') AND source NOT IN
('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7001') AND
source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN
('7003') AND source NOT IN ('service control manager') AND level IN ('error', 'warning'))
OR (id IN ('7005') AND source NOT IN ('service control manager') AND level IN ('error',
'warning')) OR (id IN ('7009') AND source NOT IN ('service control manager') AND level IN
('error', 'warning')) OR (id IN ('7011') AND source NOT IN ('service control manager')
AND level IN ('error', 'warning')) OR (id IN ('7022') AND source NOT IN ('service control
manager') AND level IN ('error', 'warning')) OR (id IN ('7023') AND source NOT IN (
('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7024') AND
source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN
('7026') AND source NOT IN ('service control manager') AND level IN ('error', 'warning'))
OR (id IN ('7030') AND source NOT IN ('service control manager') AND level IN ('error',
'warning')) OR (id IN ('7031') AND source NOT IN ('service control manager') AND strings
not like 'citrix' AND level IN ('error', 'warning')) OR (id IN ('7034') AND source NOT IN
('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7038') AND
source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN
('7041') AND source NOT IN ('service control manager') AND level IN ('error', 'warning'))
OR (id IN ('9015') AND source NOT IN ('Metaframe') AND level IN ('error', 'warning')) OR
(id IN ('9018') AND source NOT IN ('Metaframe') AND level IN ('error', 'warning')) OR (id
IN ('9026') AND source NOT IN ('Metaframe') AND level IN ('error', 'warning')) OR (id IN
('9028') AND source NOT IN ('Metaframe') AND level IN ('error', 'warning')) OR (id IN
('10009') AND source NOT IN ('DistributedCOM') AND level IN ('error', 'warning')) OR (id
IN ('10010') AND source NOT IN ('DistributedCOM') AND level IN ('error', 'warning')) OR
(id IN ('10016') AND source NOT IN ('DistributedCOM') AND level IN ('error', 'warning'))
OR (id IN ('10149') AND source NOT IN ('WindowsRemoteManagement') AND level IN ('error',
'warning')) OR (id IN ('12294') AND source NOT IN ('Directory-Services-SAM') AND level IN
('error', 'warning')) OR (id IN ('15300') AND source NOT IN ('HTTPEVENT') AND level IN
('error', 'warning')) OR (id IN ('15301') AND source NOT IN ('HTTPEVENT') AND level IN
('error', 'warning')) OR (id IN ('24679') AND source NOT IN ('Cissesrv') AND level IN
('error', 'warning')) OR (id IN ('36887') AND source NOT IN ('Schannel') AND level IN
('error', 'warning')) OR (id IN ('36888') AND source NOT IN ('Schannel') AND level IN
('error', 'warning')) OR (id IN ('40960') AND source NOT IN ('LSASRV') AND level IN
('error', 'warning')) OR (id IN ('40961') AND source NOT IN ('LSASRV') AND level IN
('error', 'warning')) OR (id IN ('45056') AND source NOT IN ('LSASRV') AND level IN
('error', 'warning'))
Numbers, constants etc
Key Safe Key Description
= eq Equals
!= ne Not equals
> gt Greater than
< lt Less than
>= ge Greater or equal than
<= le Less or equal than
in (<LIST OF VALUES>) In a given list
not in (<LIST OF VALUES>) Not in a given list
Strings
Key Safe Key Description
= eq Equals
!= ne Not equals
> gt Greater than
< lt Less than
>= ge Greater or equal than
<= le Less or equal than
in (<LIST OF VALUES>) In a given list
not in (<LIST OF VALUES>) Not in a given list
like Substring matching
regexp Regular expression
not like Opposite of like
not regexp Opposite of regexp
Syntax
Key Safe Key Description
${foo} %(foo) Expression
‘this is a string’ str(this is a string) Strings
Ns client++ icinga camp
Filter “good”
Warning
Critical
Level Source … …
Error Word … …
Error Excel … …
Info Word … …
Warning Excel … …
Error App1 … …
Warning App1 … …
Error App3 … …
filter=”source = ’App1’“
warn=”level = ’Warning’“
detail-syntax=”s: ${source} “
top-syntax=“Hello: ${list}”
Hello: s: App1, s: App1, s: App3
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
Ns client++ icinga camp
NSClient++
https://nsclient.org
Michael Medin
michael@medin.name
https://medin.name
@mickem
https://www.linkedin.com/in/mickem
Slides:
http://www.slideshare.net/MichaelMedin

More Related Content

PDF
NSClient++ whats new for 0.3.9 users
PDF
OSMC 2013 | Making monitoring simple? by Michael Medin
PDF
Nagios Conference 2013 - Michael Medin - NSClient++ Whats New
PDF
NSClient++: Monitoring Simplified at OSMC 2013
PDF
Python 炒股指南
TXT
KEY
Deploying Next Gen Systems with Zero Downtime
PDF
There's Waldo by Patrick Wardle & Colby Moore
NSClient++ whats new for 0.3.9 users
OSMC 2013 | Making monitoring simple? by Michael Medin
Nagios Conference 2013 - Michael Medin - NSClient++ Whats New
NSClient++: Monitoring Simplified at OSMC 2013
Python 炒股指南
Deploying Next Gen Systems with Zero Downtime
There's Waldo by Patrick Wardle & Colby Moore

Similar to Ns client++ icinga camp (20)

PDF
Ns client++ whats new (nwc2013)
PDF
NSClient++ Workshop: 05 Monitoring
PPTX
SSL Failing, Sharing, and Scheduling
PPTX
Fingerprint Locker using (Internet of things)
DOCX
Database Implementation Final Document
PDF
Hunting for malicious modules in npm - NodeSummit
PDF
Implementing Server Side Data Synchronization for Mobile Apps
PDF
Ss7 isup homer
PDF
Teaching Your Machine To Find Fraudsters
PPT
C C++ tutorial for beginners- tibacademy.in
PPTX
APIs and Synthetic Biology
PDF
Analyzing Log Data With Apache Spark
PDF
The Ring programming language version 1.8 book - Part 96 of 202
PDF
Eventsourcing with PHP and MongoDB
PDF
10 Rules for Safer Code
PDF
OWASP PHPIDS talk slides
PDF
Synack at ShmooCon 2015
PDF
Yapc Asia 2008 TMTOWTMS
PDF
10 Rules for Safer Code [Odoo Experience 2016]
PDF
Bulletproof
Ns client++ whats new (nwc2013)
NSClient++ Workshop: 05 Monitoring
SSL Failing, Sharing, and Scheduling
Fingerprint Locker using (Internet of things)
Database Implementation Final Document
Hunting for malicious modules in npm - NodeSummit
Implementing Server Side Data Synchronization for Mobile Apps
Ss7 isup homer
Teaching Your Machine To Find Fraudsters
C C++ tutorial for beginners- tibacademy.in
APIs and Synthetic Biology
Analyzing Log Data With Apache Spark
The Ring programming language version 1.8 book - Part 96 of 202
Eventsourcing with PHP and MongoDB
10 Rules for Safer Code
OWASP PHPIDS talk slides
Synack at ShmooCon 2015
Yapc Asia 2008 TMTOWTMS
10 Rules for Safer Code [Odoo Experience 2016]
Bulletproof

More from Michael Medin (20)

PDF
IcingaCamp Berlin 2018 NSClient++ and friends
PDF
Extending NSClient++ with rest and python
PDF
The technology of tomorrows integration plattform
PDF
Integration Plattform of Tomorrow
PDF
Automated monitoring with NSClient++ and Icinga
PDF
Continuous delivery from the trenches Redhat Forum Edition
PDF
Continuous delivery @CD Summit Stockholm
PDF
Continuous Delivery at Oracle Database Insights
PDF
Continuous delivery from the trenches
PDF
NSClient++....or not
PDF
Continuous Delivery in the Enterprise
PDF
Oracle SOA Suite 12c 1z0-434 Day 1/3
PDF
Integration in the Cloud
PDF
The Road to Oracle SOA Suite 12c
PDF
Enabling Mobility through Continuous Delivery
PDF
NSClient++ Workshop: 06 Scripting
PDF
NSClient Workshop: 04 Protocols
PDF
NSClient++ Workshop: 03 Installation
PPTX
NSClient++ Workshop: 02 Web
PDF
NSClient++ Workshop: 01 Introduction
IcingaCamp Berlin 2018 NSClient++ and friends
Extending NSClient++ with rest and python
The technology of tomorrows integration plattform
Integration Plattform of Tomorrow
Automated monitoring with NSClient++ and Icinga
Continuous delivery from the trenches Redhat Forum Edition
Continuous delivery @CD Summit Stockholm
Continuous Delivery at Oracle Database Insights
Continuous delivery from the trenches
NSClient++....or not
Continuous Delivery in the Enterprise
Oracle SOA Suite 12c 1z0-434 Day 1/3
Integration in the Cloud
The Road to Oracle SOA Suite 12c
Enabling Mobility through Continuous Delivery
NSClient++ Workshop: 06 Scripting
NSClient Workshop: 04 Protocols
NSClient++ Workshop: 03 Installation
NSClient++ Workshop: 02 Web
NSClient++ Workshop: 01 Introduction

Recently uploaded (20)

PDF
LEVERAGING SOCIAL MEDIA FOR HIGHER EDUCATION MARKETING: A CONTENT ANALYSIS AP...
PDF
Teachers Social-Emotional Learning (SEL); Ways that Impede the Development of...
PDF
Final Fanta psychology: An Investigation into Perceived Gender Stereotypes Wi...
PPTX
INTRODUCTION TO MEDIA AND INFORMATION LITERACY PPT 2.pptx
DOCX
Harnessing the Community Voices Fine Copy.docx
PDF
From Invisible to Unmissable Start My Transformation
PDF
How Prompts Become Endless Content (Without the Chaos)
PPTX
Promote Your Business Through Facebook Ads
PPTX
Social Media Plan untuk kebutuhan campaign.pptx
PPTX
Download NTLite 2025.06.10473 Crack Free
PPTX
Importance of digital marketing in daily life
PPTX
BSA Sustainability 2014 Class Presentation Sampl
PPTX
Beyond Compare 5.1.4 Build 31268 Crack For Window
DOCX
Media and Information Literacy Q1.docxxx
PDF
AI-Driven Social Media Marketing | Top Social Media Marketing Agency & Strate...
PDF
AI SOCIAL MEDIA AUDIT BY GLADYS ISRAEL .
PDF
Mastering the Digital Game: Marketing That Converts"
PPTX
Digital Marketing: Learn SEO, Social Media, PPC, Content Marketing, Email Str...
PPTX
Illuminati free agent call +256787776712,0741715666
PDF
SEO services by diginferno.com seo services
LEVERAGING SOCIAL MEDIA FOR HIGHER EDUCATION MARKETING: A CONTENT ANALYSIS AP...
Teachers Social-Emotional Learning (SEL); Ways that Impede the Development of...
Final Fanta psychology: An Investigation into Perceived Gender Stereotypes Wi...
INTRODUCTION TO MEDIA AND INFORMATION LITERACY PPT 2.pptx
Harnessing the Community Voices Fine Copy.docx
From Invisible to Unmissable Start My Transformation
How Prompts Become Endless Content (Without the Chaos)
Promote Your Business Through Facebook Ads
Social Media Plan untuk kebutuhan campaign.pptx
Download NTLite 2025.06.10473 Crack Free
Importance of digital marketing in daily life
BSA Sustainability 2014 Class Presentation Sampl
Beyond Compare 5.1.4 Build 31268 Crack For Window
Media and Information Literacy Q1.docxxx
AI-Driven Social Media Marketing | Top Social Media Marketing Agency & Strate...
AI SOCIAL MEDIA AUDIT BY GLADYS ISRAEL .
Mastering the Digital Game: Marketing That Converts"
Digital Marketing: Learn SEO, Social Media, PPC, Content Marketing, Email Str...
Illuminati free agent call +256787776712,0741715666
SEO services by diginferno.com seo services

Ns client++ icinga camp

  • 26. COLLECTD BUG FIXES REST CLIENT IMPROVED WEB UI! COUNT FIX! METRICS
  • 27. Please don’t be angry! Some times I am busy  Get over here and play NOW!
  • 49. Core
  • 52. Core Server NRPE NSCA Client NRPE check_remote NSCA notify_remote Check System check_cpu check_memory … Eventlog Check_eventlog Script Python Script Check_??? Lua Script Check_??? Misc Scheduler
  • 80. Level Source … … Error Word … … Error Excel … … Info Word … … Warning Excel … … Error App1 … … Warning App1 … … Error App3 … …
  • 81. Level Source … … Error Word … … Error Excel … … Info Word … … Warning Excel … … Error App1 … … Warning App1 … … Error App3 … … filter=”level=’error’”
  • 82. Level Source … … Error Word … … Error Excel … … Info Word … … Warning Excel … … Error App1 … … Warning App1 … … Error App3 … … filter=”source=’App1’”
  • 83. Level Source … … Error Word … … Error Excel … … Info Word … … Warning Excel … … Error App1 … … Warning App1 … … Error App3 … … filter=”source=’App1’ or source=’App3’”
  • 84. Level Source … … Error Word … … Error Excel … … Info Word … … Warning Excel … … Error App1 … … Warning App1 … … Error App3 … … filter=”source=’App1’ or source=’App3’ or level=’error’”
  • 85. Level Source … … Error Word … … Error Excel … … Info Word … … Warning Excel … … Error App1 … … Warning App1 … … Error App3 … … filter=”source=’App1’ or source=’App3’ or level=’error’ or level=’warning’”
  • 86. Level Source … … Error Word … … Error Excel … … Info Word … … Warning Excel … … Error App1 … … Warning App1 … … Error App3 … … filter=”(source=’App1’ or source=’App3’ or level=’error’ or level=’warning’) and source!=’Excel’”
  • 87. filter=”(source in (’App1’,’App3’) or level in (’error’,’warning’)) and source != ’Excel’” Level Source … … Error Word … … Error Excel … … Info Word … … Warning Excel … … Error App1 … … Warning App1 … … Error App3 … …
  • 88. • filter = (id NOT IN ('3', '4', '6', '11', '16', '23', '24', '27', '29', '36', '46', '47', '50', '56', '134', '142', '219', '267', '270', '1006', '1009', '1014', '1030', '1035', '1036', '1055', '1058', '1071', '1073', '1085', '1102', '1110', '1111', '1112', '1131', '1291', '1500', '3095', '5719', '5722', '5783', '5788', '5789', '6008', '7000', '7001', '7003', '7005', '7009', '7011', '7022', '7023', '7024', '7026', '7030', '7031', '7034', '7038', '7041', '9015', '9018', '9026', '9028', '10009', '10010', '10016', '10149', '12294', '15300', '15301', '24679', '36887', '36888', '40960', '40961', '45056') AND level IN ('error', 'warning')) OR (id IN ('3') AND source NOT IN ('FilterManager') AND level IN ('error', 'warning')) OR (id IN ('4') AND source NOT IN ('q57','L2ND') AND level IN ('error', 'warning')) OR (id IN ('6') AND source NOT IN ('Security-Kerberos') AND level IN ('error', 'warning')) OR (id IN ('11') AND source NOT IN ('Kerberos-Key- Distribution-Center') AND level IN ('error', 'warning')) OR (id IN ('16') AND source NOT IN ('WindowsUpdateClient') AND level IN ('error', 'warning')) OR (id IN ('23') AND source NOT IN ('Eventlog') AND level IN ('error', 'warning')) OR (id IN ('24') AND source NOT IN ('Time-Service') AND level IN ('error', 'warning')) OR (id IN ('27') AND source NOT IN ('Eventlog') AND level IN ('error', 'warning')) OR (id IN ('29') AND source NOT IN ('Kerberos-Key-Distribution-Center') AND level IN ('error', 'warning')) OR (id IN ('36') AND source NOT IN ('Time-Service') AND level IN ('error', 'warning')) OR (id IN ('46') AND source NOT IN ('Time-Service') AND level IN ('error', 'warning')) OR (id IN ('47') AND source NOT IN ('Time-Service') AND level IN ('error', 'warning')) OR (id IN ('50') AND source NOT IN ('TermDD','Time-Service') AND level IN ('error', 'warning')) OR (id IN ('56') AND source NOT IN ('TermDD') AND level IN ('error', 'warning')) OR (id IN ('134') AND source NOT IN ('Time-Service') AND level IN ('error', 'warning')) OR (id IN ('142') AND source NOT IN ('Time-Service') AND level IN ('error', 'warning')) OR (id IN ('219') AND source NOT IN ('Kernel-pnp') AND level IN ('error', 'warning')) OR (id IN ('267') AND source NOT IN ('Storage-agents') AND level IN ('error', 'warning')) OR (id IN ('270') AND source NOT IN ('Storage-agents') AND level IN ('error', 'warning')) OR (id IN ('1006') AND source NOT IN ('DNS Client Events','GroupPolicy') AND level IN ('error', 'warning')) OR (id IN ('1009') AND source NOT IN ('picadm') AND level IN ('error', 'warning')) OR (id IN ('1014') AND source NOT IN ('DNS Client Events') AND level IN ('error', 'warning')) OR (id IN ('1030') AND source NOT IN ('GroupPolicy') AND level IN ('error', 'warning')) OR (id IN ('1035') AND source NOT IN ('TerminalServices-RemoteConnectionManager') AND level IN ('error', 'warning')) OR (id IN ('1036') AND source NOT IN ('TerminalServices- RemoteConnectionManager') AND level IN ('error', 'warning')) OR (id IN ('1055') AND source NOT IN ('GroupPolicy') AND level IN ('error', 'warning')) OR (id IN ('1058') AND source NOT IN ('GroupPolicy') AND level IN ('error', 'warning')) OR (id IN ('1071') AND source NOT IN ('TerminalServices-RemoteConnectionManager') AND level IN ('error', 'warning')) OR (id IN ('1073') AND source NOT IN ('USER32') AND level IN ('error', 'warning')) OR (id IN ('1085') AND source NOT IN ('GroupPolicy') AND level IN ('error', 'warning')) OR (id IN ('1102') AND source NOT IN ('SNMP') AND level IN ('error', 'warning')) OR (id IN ('1110') AND source NOT IN ('GroupPolicy') AND level IN ('error', 'warning')) OR (id IN ('1111') AND source NOT IN ('Server Agents') AND level IN ('error', 'warning')) OR (id IN ('1112') AND source NOT IN ('GroupPolicy') AND level IN ('error', 'warning')) OR (id IN ('1131') AND source NOT IN ('TerminalServices- RemoteConnectionManager') AND level IN ('error', 'warning')) OR (id IN ('1291') AND source NOT IN ('NIC-agents') AND level IN ('error', 'warning')) OR (id IN ('1500') AND source NOT IN ('SNMP') AND level IN ('error', 'warning')) OR (id IN ('3095') AND source NOT IN ('Netlogon') AND level IN ('error', 'warning')) OR (id IN ('5719') AND source NOT IN ('Netlogon') AND level IN ('error', 'warning')) OR (id IN ('5722') AND source NOT IN ('Netlogon') AND level IN ('error', 'warning')) OR (id IN ('5783') AND source NOT IN ('Netlogon') AND level IN ('error', 'warning')) OR (id IN ('5788') AND source NOT IN ('Netlogon') AND level IN ('error', 'warning')) OR (id IN ('5789') AND source NOT IN ('Netlogon') AND level IN ('error', 'warning')) OR (id IN ('6008') AND source NOT IN ('Eventlog') AND level IN ('error', 'warning')) OR (id IN ('7000') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7001') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7003') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7005') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7009') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7011') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7022') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7023') AND source NOT IN ( ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7024') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7026') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7030') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7031') AND source NOT IN ('service control manager') AND strings not like 'citrix' AND level IN ('error', 'warning')) OR (id IN ('7034') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7038') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('7041') AND source NOT IN ('service control manager') AND level IN ('error', 'warning')) OR (id IN ('9015') AND source NOT IN ('Metaframe') AND level IN ('error', 'warning')) OR (id IN ('9018') AND source NOT IN ('Metaframe') AND level IN ('error', 'warning')) OR (id IN ('9026') AND source NOT IN ('Metaframe') AND level IN ('error', 'warning')) OR (id IN ('9028') AND source NOT IN ('Metaframe') AND level IN ('error', 'warning')) OR (id IN ('10009') AND source NOT IN ('DistributedCOM') AND level IN ('error', 'warning')) OR (id IN ('10010') AND source NOT IN ('DistributedCOM') AND level IN ('error', 'warning')) OR (id IN ('10016') AND source NOT IN ('DistributedCOM') AND level IN ('error', 'warning')) OR (id IN ('10149') AND source NOT IN ('WindowsRemoteManagement') AND level IN ('error', 'warning')) OR (id IN ('12294') AND source NOT IN ('Directory-Services-SAM') AND level IN ('error', 'warning')) OR (id IN ('15300') AND source NOT IN ('HTTPEVENT') AND level IN ('error', 'warning')) OR (id IN ('15301') AND source NOT IN ('HTTPEVENT') AND level IN ('error', 'warning')) OR (id IN ('24679') AND source NOT IN ('Cissesrv') AND level IN ('error', 'warning')) OR (id IN ('36887') AND source NOT IN ('Schannel') AND level IN ('error', 'warning')) OR (id IN ('36888') AND source NOT IN ('Schannel') AND level IN ('error', 'warning')) OR (id IN ('40960') AND source NOT IN ('LSASRV') AND level IN ('error', 'warning')) OR (id IN ('40961') AND source NOT IN ('LSASRV') AND level IN ('error', 'warning')) OR (id IN ('45056') AND source NOT IN ('LSASRV') AND level IN ('error', 'warning'))
  • 89. Numbers, constants etc Key Safe Key Description = eq Equals != ne Not equals > gt Greater than < lt Less than >= ge Greater or equal than <= le Less or equal than in (<LIST OF VALUES>) In a given list not in (<LIST OF VALUES>) Not in a given list
  • 90. Strings Key Safe Key Description = eq Equals != ne Not equals > gt Greater than < lt Less than >= ge Greater or equal than <= le Less or equal than in (<LIST OF VALUES>) In a given list not in (<LIST OF VALUES>) Not in a given list like Substring matching regexp Regular expression not like Opposite of like not regexp Opposite of regexp
  • 91. Syntax Key Safe Key Description ${foo} %(foo) Expression ‘this is a string’ str(this is a string) Strings
  • 94. Level Source … … Error Word … … Error Excel … … Info Word … … Warning Excel … … Error App1 … … Warning App1 … … Error App3 … … filter=”source = ’App1’“ warn=”level = ’Warning’“
  • 95. detail-syntax=”s: ${source} “ top-syntax=“Hello: ${list}” Hello: s: App1, s: App1, s: App3