Thanks that killed off one set of errors. Now something possibly a bit trickier that might need to use a regex to catch. I am getting events coming across that have the following detail below. What you will notice is there is no summary or message. Also this event comes across from about 100 different component numbers so sorting on that isn't possible. How do I match an event with no detail so that I can then drop it?
component 1577 eventClass /Unknown eventKey summary message severity Warning (3) eventState New (0) eventClassKey 1577 eventGroup syslog stateChange 2009/03/30 11:14:22.000 firstTime 2009/03/30 11:12:44.000 lastTime 2009/03/30 11:12:44.000 count 1 prodState Production (1000) suppid manager localhost agent zensyslog DeviceClass /Network/Router/Cisco Location ***** Systems |/Routers DeviceGroups | ipAddress **** facility local7 priority Warning (4) ntevid 0 ownerid clearid DevicePriority Normal (3) eventClassMapping monitor localhost -------------------- m2f -------------------- Read this topic online here: http://forums.zenoss.com/viewtopic.php?p=32802#32802 -------------------- m2f -------------------- _______________________________________________ zenoss-users mailing list [email protected] http://lists.zenoss.org/mailman/listinfo/zenoss-users
