Systems Management (OpenView-OP Mgmt) Practitioners Forum
Showing results for 
Search instead for 
Do you mean 

Monitoring custom event log

Advisor

Monitoring custom event log

Hi,

I have to monitor the following event log under Windows server 2008 SP2:

Application and services logs -> Microsoft -> Windows -> FailoverClustering -> Operational

which is the correct syntax to use in logfile encapsulator field ?
7 REPLIES
Trusted Contributor Trusted Contributor

Re: Monitoring custom event log

What version are you running OMU or OMW??
Advisor

Re: Monitoring custom event log

OMU 8.35
Advisor

Re: Monitoring custom event log

logfile path is :

%SystemRoot%\system32\Winevt\Logs\Microsoft-Windows-FailoverClustering%4Operational.evtx
Advisor

Re: Monitoring custom event log

i have tried this:

%Microsoft-Windows-FailoverClustering%4Operational_LOG%


but it doesn't work
Advisor

Re: Monitoring custom event log

Hi!

 

I've got the same Problem, but i want to Monitor those custom logs with "Windows EventLog" - Policies...

 

 

Advisor

Re: Monitoring custom event log

Highlighted
Honored Contributor Honored Contributor

Re: Monitoring custom event log

Hi,

look for the .evtx file name you want to monitor and (remove extens replace %4 with / and for log file policy add _LOG

so Microsoft-Windows-FailoverClustering%4Operationa.evtx should be %Microsoft-Windows-FailoverClustering/Operational_LOG%

Regards,
Mahmoud Ibrahim
http://www.mahmoudthoughts.com
  • Say thanks by clicking the "Kudos! Star" which is on the left.

  • Make it easier for other people to find solutions, by marking my answer with "Accept as Solution" if it solves your issue.