Description:
The Log Agent can be configured to monitor the messages occurring in the Windows event logs. It can be configured to monitor each of the following fields in an Event Message:
- Type
- Source
- Category
- Event
- User
- Computer
- Description
Solution:
Follow the below steps to configure the Log Agent to monitor a Windows Event Log message.
In this example we will monitor for a message with a Type set to"information" and the"Source" set to Application Popup.
- Launch AgentView for the caiLogA2.
- Select the LogWatchers icon.
- Select Build Event Log Pattern
- Set the Pattern to Positive Pattern
- Set the Type to Information
- Set the Source to Application Popup
- Set the rest of the fields to .*
- Select Ok.
- Now select Add Watcher
- Give the watcher a name, ie, Test_Watcher
- Give the Log File as SYSTEM_LOG\System
- The positive pattern comes there automatically as we have already configured when building the watcher
- Leave the Positive Toggle Pattern, Negative Pattern and Negative Toggle Pattern as Blank
- Set the Status Policy as Poll EOF
- Set the Trap Send Policy as Once
- Set the History Policy as Generate
- Set the Match Trap Policy as Do Not Send
- Set the Monitor Status as Monitor Critical
- Now click Ok