[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Bigsister-general] eventlog filtering on windows 2003


I have tried to filter out certain repeatedly returning alerts which are known in win2003 server but until now im unsuccessful.

Could somebody push me in the right direction?

in the eventlog I have added the following two last lines

System:


default green 0
System looks fine
The (.*) disk is at or near capacity red 20
$1 fs full
Source=([^;]+);.*scsi
red 15 $1: scsi error
Source=([^;]+);.*notice
yellow 15 $1: notice
Source=([^;]+);.*warning
yellow 15 $1: warning
Source=([^;]+);.*fatal
yellow 15 $1: fatal error
Source=([^;]+);.*Severity=1: (.*) red
15 $1: serious error: $2
Source=([^;]+);.*Severity=2: (.*) yellow
15 $1: error: $2
Source=(LsaSrv);.* green 0 LsaSrv error but known
error no impact
Source=(DnsApi);.* green 0 DnsApi error but known
error no impact


To filter out the following two system warnings:

Date : x/x/x Source : LSASRV
time :x:x:x Category: SPNEGO (negotiator)
Type : warning Event ID : xxxxx
user : N/A
Computer : SMTP

The Security System could not establish a secured
connection with the server DNS/ns1.kpnhs.nl. No
authentication protocol was available.

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

Data 0000: c0000388



and the second one

The Security System detected an authentication error
for the server DNS/ns1.kpnhs.nl. The failure code from
authentication protocol Kerberos was "There are
currently no logon servers available to service the logon
request.
(0xc000005e)".

For more information, see Help and Support Center at
http://go.microsoft.com/fwlink/events.asp.

data 0000: c0000005e


-------------------------------------------------------
SF email is sponsored by - The IT Product Guide
Read honest & candid reviews on hundreds of IT Products from real users.
Discover which products truly live up to the hype. Start reading now.
http://ads.osdn.com/?ad_id=6595&alloc_id=14396&op=click
_______________________________________________
Bigsister-general mailing list
suppressed
https://lists.sourceforge.net/lists/listinfo/bigsister-general


Mail converted by mhonarc 2.6.15
This archive provided courtesy of JSW4.NET, Internet Hosting Services for Small Business.