- Community Home
- >
- Networking
- >
- IMC
- >
- Re: Trying syslog to alarm in HP iMC, problem with...
Categories
Company
Local Language
Forums
Discussions
Forums
- Data Protection and Retention
- Entry Storage Systems
- Legacy
- Midrange and Enterprise Storage
- Storage Networking
- HPE Nimble Storage
Discussions
Discussions
Discussions
Forums
Discussions
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
- BladeSystem Infrastructure and Application Solutions
- Appliance Servers
- Alpha Servers
- BackOffice Products
- Internet Products
- HPE 9000 and HPE e3000 Servers
- Networking
- Netservers
- Secure OS Software for Linux
- Server Management (Insight Manager 7)
- Windows Server 2003
- Operating System - Tru64 Unix
- ProLiant Deployment and Provisioning
- Linux-Based Community / Regional
- Microsoft System Center Integration
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Discussion Boards
Community
Resources
Forums
Blogs
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-04-2017 02:16 AM - edited 12-04-2017 02:17 AM
12-04-2017 02:16 AM - edited 12-04-2017 02:17 AM
Trying syslog to alarm in HP iMC, problem with Template Content
Hello,
I have a syslog template created from this syslog trap:
<15> Dec 4 11:10:40 192.168.194.82 1X : 1X m8021xCtrl:Port 3: Received Auth Failure for client 5cff35-00512f, finished authentication session for RyC.
I created the syslog tempate with this Template Content:
<*> *:*:* $(DeviceIP) 1X : 1X m8021xCtrl:Port $(DevicePort): Received Auth Failure for client $(UserMAC), finished authentication session for $(UserName).
If I create a syslog to alarm, it rules correctly, but, if I show the "DeviceIP" param, I get the Ip address with date's seconds at left:
40 192.168.194.82.
40=seconds from original date (Dec 4 11:10:40)
192.168.194.82 = Ip address
How should I write the "Template Content" creating my syslog template to show only the IP?
I have tried *, %, ??, etc, but I can't show it without date's seconds.
Thans.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
12-21-2017 04:24 AM
12-21-2017 04:24 AM
Re: Trying syslog to alarm in HP iMC, problem with Template Content
I'm not sure but could be that the "SourceIP" is better then "DeviceIP". Check the content of the syslog and try again.