Greetings,
My Monilog reports do not return any data even though the logs being analysed have relevant events. The foot of the report states:
"The logs for the selected time interval exist and contain events but none of them match the selected criteria"
This indicates that Monilog can access the log file and that it's contents are meaningful. I have checked the hints which follow this message but my configuration appears OK with the possible exception of the hint "the EventReporter settings are not configured properly for MoniLog so expected fields are missing".
My configuration details are as follows:
EventReporter V5.4.163
---------------------------
EventReporter runs on each of out windows 2000 hosts and send logs to our syslog server (Solaris). This configuration works fine and aggregated Windows logs appear at a single location on the UNIX box. The
EventReporter clients are configured to "Use Monilog" and the "Use legacy format" and "Add FacilityString" check boxes are checked in the General tab of each client.
Monilog v2.0.137
------------------
Monilog runs on a Windows host with access to the syslog log files which hold the aggregated windows events.
I have set up a monilog profile with "Servers to analyse' = "*' and the report options set to report on all event types for the last 24 hours. There are **definitely** log entries in the log file being analysed which satisfy this criteria. an example entry follows (hostname = "evalce"):
<snip>
Apr 28 09:34:54 evalce EvntSLog:787553: [WRN] Sun Apr 28 03:34:22 2003: N\A/System/EVALCE/NETLOGON (5773) - "The DNS server for this DC does not support dynamic DNS. Add the DNS records from the file 'SystemRoot\System32\Config\netlogon.dns' to the DNS server serving the domain referenced in that file."
<snip>
Help !!
--------
Can anyone verify that the log entry above is in the correct format.
Can anyone supply me with the working configuration for the General tab in Monilog for my setup (Windows EventReporter/Solaris syslog).
Can anyone suggest more specific reasons why my config is failing to populate the Monilog report.
Thanks in advance
Tony


