In message <f2d1f8d64307c04895f29cc9b70b265401c68...@defrm203.emea.corp.eds.com
>,
"Hayward, Ben" writes:
>I have a challenge to have SEC trigger upon log NOT having a current
>time stamp on the file. The challenge is that the application
>sometimes hangs, NOT writing to log. I suppose I could look for
>current time stamp in last log line? 
> 
>Any help from the esteemed group is greatly appreciated 

Does the solution in:

   http://www.cs.umb.edu/~rouilj/sec/sec_paper_full.pdf

in section 3.4 "Detecting Missing Events" see like it would work for you?

I use a similar method to look for a hung nagios server by watching
the log file and requiring a new line to be written to it least once
a minute.

--
                                -- rouilj
John Rouillard
===========================================================================
My employers don't acknowledge my existence much less my opinions.





------------------------------------------------------------------------------
OpenSolaris 2009.06 is a cutting edge operating system for enterprises 
looking to deploy the next generation of Solaris that includes the latest 
innovations from Sun and the OpenSource community. Download a copy and 
enjoy capabilities such as Networking, Storage and Virtualization. 
Go to: http://p.sf.net/sfu/opensolaris-get
_______________________________________________
Simple-evcorr-users mailing list
Simple-evcorr-users@lists.sourceforge.net
https://lists.sourceforge.net/lists/listinfo/simple-evcorr-users

Reply via email to