Kaseya Community

Best way to configure event monitoring?

  • Hi all,

    I had all this working, but it seems that recently it isn't working like it used to...

    At the moment I am trying to monitor events from the Application and System logs for all Errors, Warnings and Critical using the All Events option and then have a seperate Event Set with my ignore options...

    So it is like this...

    Log Type: Application
    ATSE EWISFCV: A--- EW---C-
    Event Set: All Events
    Interval: 1
    Duration: 1 Day
    Re-Arm: 1 Day

    Same for my ignore set (just the "Event Set" option is the name of my set with the ignores in it)

    This is just for workstations, hence the 1 day options... I don't really need to know if the same alert happens more then once in a day on a workstation, plus i don't want to get flooded with alerts.

    Problem is, I don't seem to be getting ANY alerts... and i have no idea why...

    Also eventually I'd like to get some particular alerts emailing me when they occur... so what is the best way to have all this setup? I've tried different things but at the moment it doesn't appear to be working at all!

    Thanks

    Legacy Forum Name: Best way to configure event monitoring?,
    Legacy Posted By Username: KRiSX
  • I'd suggest running a report against the workstations you have applied the event sets against and see if it returns any data.

    Also, what we do is take this same report and schedule it to run once a day and set it to email to our helpdesk. That way we get one email to go through over a few minutes, versus a whole lot a emails flooding us through out the day.

    Legacy Forum Name: Event Sets,
    Legacy Posted By Username: boudj
  • thanks for the reply, but i guess i'm still trying to work out if it is safe to have All Events selected as well as have an event set with ignores in it?

    It seems to be blocking everything from what i can tell

    Legacy Forum Name: Event Sets,
    Legacy Posted By Username: KRiSX
  • Check and make sure that you have event logging enabled for those agents.

    You can find this under the tab Agent > Event Log Settings (the 4th function item down) After you check that also check that you dont have any red letters for the event set monitoring. The red letters mean that logging is currently disable for that log.

    As far as event logging and reporting - I would suggest to try and use one event log, like what you are doing. From that log I would then select what events to ignore from processing the log. That way you only have one event set running and not multiple event sets monitoring certain logs (I am currently working on this one for the Library).

    Currently I have it set up for the All Events for Errors only to Alarm. Then I have several Kaseya created event sets that only alarm upon errors. Though I do have to agree with boudj that the reporting sounds really good and automates the process even more. Good suggestion Boudj.

    Legacy Forum Name: Event Sets,
    Legacy Posted By Username: cking@faylib.org
  • cking@faylib.org
    Check and make sure that you have event logging enabled for those agents.

    You can find this under the tab Agent > Event Log Settings (the 4th function item down) After you check that also check that you dont have any red letters for the event set monitoring. The red letters mean that logging is currently disable for that log.

    As far as event logging and reporting - I would suggest to try and use one event log, like what you are doing. From that log I would then select what events to ignore from processing the log. That way you only have one event set running and not multiple event sets monitoring certain logs (I am currently working on this one for the Library).

    Currently I have it set up for the All Events for Errors only to Alarm. Then I have several Kaseya created event sets that only alarm upon errors. Though I do have to agree with boudj that the reporting sounds really good and automates the process even more. Good suggestion Boudj.


    I have checked the Event Log Settings many many times and i'm still getting nothing... thing is if i go to the Agent Logs option and view recent event log events... it does show recent items... items that i should be getting alerted to according to my monitoring settings...

    Event Log Settings are set to Application EW---C- System EW---C-

    Under Alerts in the monitoring tab I currently have " selected" and applied for Application and System logs

    A---
    EW-----

    Interval is 1
    Duration is blank
    Re-Arm is 12 hr

    by that i assume it shold only alert to a single event id once every 12 hours... so instead of getting multiple identical alerts for the one machine i should just get it once... but i'm not getting anything!


    EDIT: also just checking the Statistics page i see this .... "Pending Alerts 56476" thats a LOT of alerts... yet... i can't see any of them!!

    Legacy Forum Name: Event Sets,
    Legacy Posted By Username: KRiSX
  • I am having the same issue. I have created an event set to monitor avast's event log and alert me if it finds a virus:
    
    <?xml version="1.0" encoding="ISO-8859-1" ?>
    <event_sets>
      <set_elements setName="Avast" eventSetId="91819368">
        <element_data ignore="0" source="*avast*" category="*" eventId="90" username="*" description="*"/>
      </set_elements>
    </event_sets>
    
     A--E
    EW-----   mike@***.com
    Avast   
    
    
    I am getting no alerts, and no emails. 
    
    If I check the antivirus log for the agent, the event sets are there (I ran some test viruses on the test client)
    
    
    any ideas?

    Legacy Forum Name: Event Sets,
    Legacy Posted By Username: Resistance2Fly


    [edited by: Brendan Cosgrove at 5:34 PM (GMT -8) on 12-17-2010] .
  • i seem to have solved my issues... not exactly sure what i did to fix or should i say what step i took fixed the issue...

    but i went into the System tab > Configure and first i think i did a Reload of all the hotfixes... second I hit "Reapply Schema" and i may of also done a defrag database... can't recall right this second.

    either way all appears to be well at the moment, except for the classic console screen timing out... anyone got any tips for fixing that?

    Legacy Forum Name: Event Sets,
    Legacy Posted By Username: KRiSX
  • re-applying the hotfixes worked for me too, thanks!

    Legacy Forum Name: Event Sets,
    Legacy Posted By Username: Resistance2Fly