alert on the absence of syslog data

Has anyone done this?  Any device we syslog normally is sending a sufficiently constant stream of syslog data..

Is there a way to alert to the absense of data? Something like "no syslog data received from device in X minutes"

Thanks,

Wade

Parents
  • Hi Wade, do you mean Syslog Device listening in InTrust Deployment manager or Syslog scheduled gathering via nix agent? In the first case the answer is negative, in the second case positive. You can use Missing Event rule wizard to create the new missing event type rule and apply it to Linux Syslog data source. Feel free to ask questions if have problems while doing this.

Reply
  • Hi Wade, do you mean Syslog Device listening in InTrust Deployment manager or Syslog scheduled gathering via nix agent? In the first case the answer is negative, in the second case positive. You can use Missing Event rule wizard to create the new missing event type rule and apply it to Linux Syslog data source. Feel free to ask questions if have problems while doing this.

Children
No Data