<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IMC Syslog Template matching in IMC</title>
    <link>https://community.hpe.com/t5/imc/imc-syslog-template-matching/m-p/6949046#M3653</link>
    <description>&lt;P&gt;Hi!&lt;BR /&gt;&lt;BR /&gt;We are currently implemting some rules to upgrade syslog messages to traps. We are looking to have different pools on our loadbalancer mail different application teams in the event when a pool loses all it's members (unfortunately there are no traps that give enough granularity).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We have configured different syslog templates to be matched, but are running into issues that a particular rule is getting matched everytime. For example let's say we have 3 pools:&lt;BR /&gt;APP-POOL1&lt;BR /&gt;APP-POOL11&lt;BR /&gt;APP-POOL18&lt;BR /&gt;&lt;BR /&gt;The syslogmessage reads "no available members for pool APP-POOLxx". When pool 11 or 18 go down, IMC matches the pool 1 message, because the syslogtemplate is the same for this part "&lt;SPAN&gt;no available members for pool APP-POOL1". When I disable the APP-POOL1 rule, everything works fine, because the only rules to match are 11 and 18.&lt;BR /&gt;Is there a way in IMC to work around this? Can I tell IMC to look at the whole syslogmessage instead of only at the first part when it gets matched?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 17 Mar 2017 12:56:03 GMT</pubDate>
    <dc:creator>Johan de Greef</dc:creator>
    <dc:date>2017-03-17T12:56:03Z</dc:date>
    <item>
      <title>IMC Syslog Template matching</title>
      <link>https://community.hpe.com/t5/imc/imc-syslog-template-matching/m-p/6949046#M3653</link>
      <description>&lt;P&gt;Hi!&lt;BR /&gt;&lt;BR /&gt;We are currently implemting some rules to upgrade syslog messages to traps. We are looking to have different pools on our loadbalancer mail different application teams in the event when a pool loses all it's members (unfortunately there are no traps that give enough granularity).&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We have configured different syslog templates to be matched, but are running into issues that a particular rule is getting matched everytime. For example let's say we have 3 pools:&lt;BR /&gt;APP-POOL1&lt;BR /&gt;APP-POOL11&lt;BR /&gt;APP-POOL18&lt;BR /&gt;&lt;BR /&gt;The syslogmessage reads "no available members for pool APP-POOLxx". When pool 11 or 18 go down, IMC matches the pool 1 message, because the syslogtemplate is the same for this part "&lt;SPAN&gt;no available members for pool APP-POOL1". When I disable the APP-POOL1 rule, everything works fine, because the only rules to match are 11 and 18.&lt;BR /&gt;Is there a way in IMC to work around this? Can I tell IMC to look at the whole syslogmessage instead of only at the first part when it gets matched?&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2017 12:56:03 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/imc-syslog-template-matching/m-p/6949046#M3653</guid>
      <dc:creator>Johan de Greef</dc:creator>
      <dc:date>2017-03-17T12:56:03Z</dc:date>
    </item>
    <item>
      <title>Re: IMC Syslog Template matching</title>
      <link>https://community.hpe.com/t5/imc/imc-syslog-template-matching/m-p/6949755#M3666</link>
      <description>&lt;P&gt;Hmmm. Looks like a regex problem. You might be able to do something with putting in a more complex regex match.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Mar 2017 21:04:45 GMT</pubDate>
      <guid>https://community.hpe.com/t5/imc/imc-syslog-template-matching/m-p/6949755#M3666</guid>
      <dc:creator>LindsayHill</dc:creator>
      <dc:date>2017-03-20T21:04:45Z</dc:date>
    </item>
  </channel>
</rss>

