HOME DOWNLOAD ORDER & PRICING RESELLERS CONTACT

SyslogServer Suite

Presentation >>

Software components

Customer Support

3. Basic filters design

The filters window can be opened in two different ways; either by choosing menu filter, Create or by right-clicking on an entry and choosing 'Create a filter based on this entry'. In the latter case, an already prepared filter is presented - matching exactly the current entry. Below is the basic 'Create filter' window. The hosts and processes that have been identified appear in drop-down menus. This information is updated upon startup of SyslogView, by default. Settings for updating these is can be found in menu tools, options.

 


These are the available fields:

Button Negative filter rule: decides if the specified filter will prevent certain entries from appearing.

Drop-down Facility: Specify which facility the entries have to belong to. On many syslog clients, for instance Datagram's SyslogAgent, which facility to use can be specified. It is therefore a suitable basis for classification of entry type. A range of custom facilities are available, Local0 to Local7.

Drop-down Severity and drop-down compare rule: Specify which severity the entries have to belong to. They can be specified to a specific Severity, or to a range of severities by using the compare drop-down option. For instance 'Notice <=' means 'Where severity is equal or more severe than Notice'.

List item Host: Specify which host or hosts en entry has to come from. It could happen that en entry appear in this list that is not a real host. The reason could be that Syslogserver did not recognize the format in which it was sent, and therefore used the specification RFC3164 as a guide. Please notify us at info@syslogserver.com for any such occurrence.

Drop-down Process: specify which process, if any, the entries must have. Similar to the host list item, false entries could appear on the same basis. Please notify us at info@syslogserver.com for any such occurrence.

Button Edit Query: From all the above configuration options, the corresponding SQL query is dynamically constructed in the text area to the right of the button. By pressing the Edit Query button you are given the opportunity to modify the actual SQL query. This is good for advanced use of filters. See the later chapters for more information.

Text string Filter name: This is the displayed name of the filter when created.

Button Save and Exit: This completes the filter design. Upon exit, SyslogView also confirms that the SQL syntax is valid. Activate the filter by choosing it from the filter menu. An active filter has a check mark next to it.


Next: Basic filter design, continued

Contents:
1. Introduction
2. Using filters
3. Basic filter design
4. Basic filter design, continued
5. Alarms are similar to filters
6. Using filter groups
7. Advanced filter design
8. Advanced filter design, continued
9. Conclusion

© 2008 Datagram Consulting Sweden. All rights reserved.