You are here

check_eventlog syntax for substring in log body

2 posts / 0 new
Last post
theodor.macris_86865
theodor.macris_86865's picture
check_eventlog syntax for substring in log body

Using nsclient++ .4.3 what is the correct syntax for looking in the event message body for a substring? I am using OpsView pro. I cannot find any info on the new syntax.

This does not work, fails to validate.

-H "hostname.domain.com" -c check_eventlog -a "scan-range=-10m" "truncate-message=1023" "file=system" "warn=none" "crit=count>0" "filter=level='error' AND id='108' AND source='Cfengine Nova' AND message=substr:'mySubstring' "

theodor.macris_86865
theodor.macris_86865's picture
ACK, it uses SQL type

ACK, it uses SQL type operators. Wish I could find that documented somewhere. 

message LIKE 'my substring'