Alerting the administrator of a telnet to router or a switch is possible with Syslog monitoring
Syslog monitoring in OpManager provides a rule-based method of reading syslogs and associating alerts to these syslogs to notify admins or perform other network management tasks. OpManager’s Syslog daemon supports a wide number of devices across multiple platforms. It supports any syslog-exporting device or applications such as Servers (Linux, UNIX, AIX and Solaris), routers, switches, etc.
Follow the steps given below to add Syslog Rules:
Syslog is a client/server protocol that sends event notification messages to the syslog receiver. These event notification messages (usually called syslog messages) help in identifying the authorized and unauthorized activities such as installing software, accessing files, illegal logins etc. that take place in the network. In OpManager, Syslog rules help notify you when particular syslog messages such as kernel messages, system daemons, user level messages, etc. are sent by the devices.
Apart from the pre-defined syslog rules you can also add any number of syslog rules. Here are the steps to add a syslog rule:
Enter the Alarm Message.
Note:
In addition to plain text matching, the Match Text field supports regular expressions (Regex). You can use Regex patterns to match syslog messages based on multiple conditions, alternatives, or exclusions.
For example, consider the sentence "session closed for user root".
| Condition | Regex Pattern | Example Usage |
|---|---|---|
| AND | (?=.*XXX)(?=.*YYY) | (?=.*session)(?=.*root) |
| OR | (XXX)|(YYY) | (closed)|(opened) |
| NOT | ^(?!.*XXX).*$ | ^(?!.*user).*$ |
Click the Advanced button to configure advanced (threshold) rules. This is optional.
To clear or rearm the event: