Apologies if this has been asked before - tried various searches but didn't come up with anything.
I'm experimenting with an SiS monitor to find things in a Solaris messages file, when a match is detected send an email. I'm trying to get this working on SiS 11.20 on Win Server 2003 EE SP2.
No matter how I configure the log file monitor, it will not send an email. I know the email alerting works as I'm doing pretty much the same with SNMP traps that are being captured by SiS i.e. SNMP trap arrives from device, content of trap is sent by email as the alerting action.
As far as the log file monitor definition is concerned, I am using a regex in the Content Match field which matches the specific structure of the entry in the messages file I am interested in - the regex works in that if I use the regex Open Tool I can type in various strings that I might expect to find in the file and the regex matches the whole thing.
I created a new group, created a new monitor in the group with the regex and threshold as described. I then created a new email alert and attached this to the group (also tried attaching to the monitor).
When I inject a message into the log file and then run the monitor it finds the string and shows a match in error on the dashboard for the monitor but doesn't send an email. I tried a couple of log file injections, same results.
I tested the newly created alert and this does send an email.
Attached are screen shots of the monitor status and history views.
Is there a specific log file on my SiS server that I can go and have a look through? Is it possible to run in debug?
I've got it all working the way I want. Went back to basics as you suggested and gradually built up the regex to pattern match the full message and hey presto it works. The regex I'm using now is a little different to the original I posted, I discovered a subtle difference in the way the original was pattern matching and have made a change.