You could do something similar to rule 1002, but set it to a low level.
On Mon, Feb 7, 2011 at 5:32 AM, Js Opdebeeck <[email protected]> wrote: > Hello; > > > Due to some 'bugs' and errors that can't be quickly solved by the operation, > many Severity 13 messages are flooding my logs. > Is there a method to quickly create a "Mute" list based on Keywords (and > make them low priority, don't send email)? > > Sample noisy message (especialy for MsWindows that generate extra large > messages) > > 2011 Feb 07 09:33:32 Rule Id: 1003 level: 13 > Location: 192.168.20.190->/data/network_forward_nl.log > Non standard syslog message (size too large). > Feb 7 09:33:31 10.10.10.5 9: 33:37 AM AMSEXIAPP:VBRuntime Error 1 The VB > Application identified by the event source logged this Application > BatchService: Thread ID: 1228 ,Logged: > <Error><Message><CodeTableEntry><CodeId>518</CodeId><Code>ErrorMessages</Code></CodeTableEntry><Parameters><Parameter > NAME = ReplacementError ><![CDATA[Cannot generate SSPI context > ]]></Parameter></Parameters></Message><Source>Microsoft OLE DB Provider for > SQL Server BACMDE.CCmdExec:GetConnection:80 > BACMDE.CCmdExec:ICommandExecutor_Execute:890 > BABOBB.CObjectBroker:RecordBasedSave : Execute statement > BABOBB.CObjectBroker:ISetBasedBroker2_Save : Delegate BAPMSELC 4.5.0 > BAPMSELB.CEventLog:CIEventLog_LogEvent::190</Source><NativeError><ErrorCode>-2147467259</ErrorCode><Source>Microsoft > OLE DB Provider for SQL Server BACMDE.CCmdExec:GetConnection:80 > BACMDE.CCmdExec:ICommandExecutor_Execute:890 > BABOBB.CObjectBroker:RecordBasedSave : Execute statement > BABOBB.CObjectBroker:ISetBasedBroker2_Save : Delegate BAPMSELC 4.5.0 > BAPMSELB.CEventLog:CIEvent > > Kind regards > > Js > >
