Re: [Simple-evcorr-users] Monitoring a log for a string and executing a command

2015-07-15 Thread Mohan
Hi, I have been looking for c/c++ implementation of CEP engine for event correlation functionality. Any Tools available? Please reply if you know any. I have been using and playing around with a simple event correlator (SEC) an open source found in sourceforge website but it's written in perl. I

[Simple-evcorr-users] problem with sec loosing stdin

2015-07-15 Thread David Lang
I have rsyslog starting sec with lines like: action(type=omprog name=sec-heartbeat binary=/usr/bin/sec --conf=/etc/sec/missing-logs --intevents --intcontexts --dump=/tmp/dumpfile.missing-logs --debug=5 --log=/var/log/sec-missing-logs --input - template=manual hup.signal=USR2) I'm running into

Re: [Simple-evcorr-users] problem with sec loosing stdin

2015-07-15 Thread Risto Vaarandi
Hi David, I noticed that sec is running without --notail option, but this causes sec to stay around even after rsyslog has closed the write end of the pipe. I would suggest including the --notail option in the sec command line which causes it to exit when rsyslog closes the pipe (for more

Re: [Simple-evcorr-users] problem with sec loosing stdin

2015-07-15 Thread David Lang
On Wed, 15 Jul 2015, Risto Vaarandi wrote: Hi David, I noticed that sec is running without --notail option, but this causes sec to stay around even after rsyslog has closed the write end of the pipe. I would suggest including the --notail option in the sec command line which causes it to