Hi,
I'm trying to build
a ruleset that looks something like this (see below) I am not a seasoned
ruleset builder so please keep that in mind if you reply!
->
Action - Email (historical log of node Down trap)
->
->Node Down Trap ->
->
->
Event Stream
-> ->
Reset on Match -> Pager -> Action
- Email (historical log of paged event)
->
->
->Node Up Trap ->
This works just fine
but has not event attribute filtering (like source host). If I insert an
Event Attribute #2 right after the Event Stream or before the Pager - it works
perfectly. Problem is, I want to query a smartset because I have so many
different hosts that need this rule. When I do insert the Query Smartset
(in either of the 2 positions described above) - the rule stops
functioning. I am using Object ID Source = 2 and using a smartset that
includes the servers I want to monitor.
Any
thoughts?
Glen Warn
PEMCO Corporation Computer Services
(PCCS)
206-628-5770
|