From martin.flemming@desy.de Wed Jun 24 08:21:21 2026 From: martin.flemming@desy.de To: xymon@xymon.com Subject: [Xymon] double LOG alert Date: Wed, 08 Feb 2012 13:52:17 +0100 Message-ID: MIME-Version: 1.0 Content-Type: multipart/mixed; boundary="===============0410269891720407079==" --===============0410269891720407079== Content-Type: text/plain; charset="utf-8" Content-Transfer-Encoding: quoted-printable Hi ! I've got two alert mails for the same logentry within 30 minutes :-( I know that becomes with the default of "the LOG check clears itself after 30m" didn't it ? Is it possible to eliminate this without hacking the sourcecode ? Thanks & Cheers Martin ______________________________________________________ FRIST ALERT : ---------- Forwarded message ---------- Date: Wed, 8 Feb 2012 10:16:37 +0100 (CET) From: Xymon user To: xymon-patrol at desy.de, oracle-admins at desy.de Subject: [xymon-patrol] Xymon [652105] oracle1:msgs CRITICAL (RED) [cfid:128] red System logs at Wed Feb 8 10:16:28 CET 2012 &red Critical entries in /var/log/messages &red Feb 8 10:14:25 oracle1 kernel: ip_tables: (C) 2000-2006 Netfilter Core = Team &red Feb 8 10:14:25 oracle1 kernel: nf_conntrack version 0.5.0 (16384 bucket= s, 65536 max) &red Feb 8 10:14:25 oracle1 kernel: CONFIG_NF_CT_ACCT is deprecated and will= be removed soon. Please use &red Feb 8 10:14:25 oracle1 kernel: nf_conntrack.acct=3D1 kernel parameter, = acct=3D1 nf_conntrack module option or &red Feb 8 10:14:25 oracle1 kernel: sysctl net.netfilter.nf_conntrack_acct= =3D1 to enable it.




Full log /var/log/messages
Feb  8 10:14:25 oracle1 kernel: ip_tables: (C) 2000-2006 Netfilter Core Team
Feb  8 10:14:25 oracle1 kernel: nf_conntrack version 0.5.0 (16384 buckets, 65=
536 max)
Feb  8 10:14:25 oracle1 kernel: CONFIG_NF_CT_ACCT is deprecated and will be r=
emoved soon. Please use
Feb  8 10:14:25 oracle1 kernel: nf_conntrack.acct=3D1 kernel parameter, acct=
=3D1 nf_conntrack module option or
Feb  8 10:14:25 oracle1 kernel: sysctl net.netfilter.nf_conntrack_acct=3D1 to=
 enable it.


SECOND ALERT :


Date: Wed,  8 Feb 2012 10:46:45 +0100 (CET)
From: Xymon user 
To: xymon-patrol at desy.de, oracle-admins at desy.de
Subject: [xymon-patrol] Xymon [652105] oracle1:msgs CRITICAL (RED) [cfid:128]

red System logs at Wed Feb  8 10:46:32 CET 2012

&red Critical entries in /var/log/messages
&red Feb  8 10:14:25 oracle1 kernel: ip_tables: (C) 2000-2006 Netfilter Core =
Team
&red Feb  8 10:14:25 oracle1 kernel: nf_conntrack version 0.5.0 (16384 bucket=
s, 65536 max)
&red Feb  8 10:14:25 oracle1 kernel: CONFIG_NF_CT_ACCT is deprecated and will=
 be removed soon. Please use
&red Feb  8 10:14:25 oracle1 kernel: nf_conntrack.acct=3D1 kernel parameter, =
acct=3D1 nf_conntrack module option or
&red Feb  8 10:14:25 oracle1 kernel: sysctl net.netfilter.nf_conntrack_acct=
=3D1 to enable it.





Full log /var/log/messages
Feb  8 10:14:25 oracle1 kernel: ip_tables: (C) 2000-2006 Netfilter Core Team
Feb  8 10:14:25 oracle1 kernel: nf_conntrack version 0.5.0 (16384 buckets, 65=
536 max)
Feb  8 10:14:25 oracle1 kernel: CONFIG_NF_CT_ACCT is deprecated and will be r=
emoved soon. Please use
Feb  8 10:14:25 oracle1 kernel: nf_conntrack.acct=3D1 kernel parameter, acct=
=3D1 nf_conntrack module option or
Feb  8 10:14:25 oracle1 kernel: sysctl net.netfilter.nf_conntrack_acct=3D1 to=
 enable it.




--===============0410269891720407079==--


From martin.flemming@desy.de Wed Jun 24 08:21:24 2026
From: martin.flemming@desy.de
To: xymon@xymon.com
Subject: [Xymon] double LOG alert
Date: Wed, 29 Feb 2012 11:35:37 +0100
Message-ID: 
In-Reply-To: 
MIME-Version: 1.0
Content-Type: multipart/mixed; boundary="===============2295095434469176878=="

--===============2295095434469176878==
Content-Type: text/plain; charset="utf-8"
Content-Transfer-Encoding: quoted-printable


Hi and once again :-)


It seems to be a bug for me to got 2 alert-mails within 30 minutes
for still the same event/logentry, isn't it ?

Ok, the reason of the second needless log-mail-alert is,
that ther are no further logentries in the next 30 minutes,
it's very unusual for a logfile i know, but what should i do,
to oppress the second needless alert ?

Is there any chance to clear the "LOG check"  by hand
without changing the sourcecode
http://lists.xymon.com/archive/2006-December/010927.html

or maybe a special alert-configuration ?

Thanks in advance

cheers,
 	martin


On Wed, 8 Feb 2012, Martin Flemming wrote:

>
> Hi !
>
> I've got two alert mails for the same logentry within 30 minutes :-(
>
> I know that becomes with the default of
>
> "the LOG check clears itself after 30m"
>
> didn't it ?
>
> Is it possible to eliminate this without hacking the sourcecode ?
>
> Thanks & Cheers
>
>       Martin
>
>
> ______________________________________________________
>
> FRIST ALERT :
>
> ---------- Forwarded message ----------
> Date: Wed,  8 Feb 2012 10:16:37 +0100 (CET)
> From: Xymon user 
> To: xymon-patrol at desy.de, oracle-admins at desy.de
> Subject: [xymon-patrol] Xymon [652105] oracle1:msgs CRITICAL (RED) [cfid:12=
8]
>
> red System logs at Wed Feb  8 10:16:28 CET 2012
>
> &red Critical entries in  href=3D"/xymon-cgi/svcstatus.sh?CLIENT=3Doracle1&SECTION=3Dmsgs:/var/lo=
g/messages">/var/log/messages
> &red Feb  8 10:14:25 oracle1 kernel: ip_tables: (C) 2000-2006 Netfilter Cor=
e=20
> Team
> &red Feb  8 10:14:25 oracle1 kernel: nf_conntrack version 0.5.0 (16384=20
> buckets, 65536 max)
> &red Feb  8 10:14:25 oracle1 kernel: CONFIG_NF_CT_ACCT is deprecated and wi=
ll=20
> be removed soon. Please use
> &red Feb  8 10:14:25 oracle1 kernel: nf_conntrack.acct=3D1 kernel parameter=
,=20
> acct=3D1 nf_conntrack module option or
> &red Feb  8 10:14:25 oracle1 kernel: sysctl net.netfilter.nf_conntrack_acct=
=3D1=20
> to enable it.
>
> 
> 
>
> 
> > > Full log href=3D"/xymon-cgi/svcstatus.sh?CLIENT=3Doracle1&SECTION=3Dmsgs:/var/lo= g/messages">/var/log/messages > Feb 8 10:14:25 oracle1 kernel: ip_tables: (C) 2000-2006 Netfilter Core Team > Feb 8 10:14:25 oracle1 kernel: nf_conntrack version 0.5.0 (16384 buckets, = > 65536 max) > Feb 8 10:14:25 oracle1 kernel: CONFIG_NF_CT_ACCT is deprecated and will be= =20 > removed soon. Please use > Feb 8 10:14:25 oracle1 kernel: nf_conntrack.acct=3D1 kernel parameter, acc= t=3D1=20 > nf_conntrack module option or > Feb 8 10:14:25 oracle1 kernel: sysctl net.netfilter.nf_conntrack_acct=3D1 = to=20 > enable it. > > > SECOND ALERT : > > > Date: Wed, 8 Feb 2012 10:46:45 +0100 (CET) > From: Xymon user > To: xymon-patrol at desy.de, oracle-admins at desy.de > Subject: [xymon-patrol] Xymon [652105] oracle1:msgs CRITICAL (RED) [cfid:12= 8] > > red System logs at Wed Feb 8 10:46:32 CET 2012 > > &red Critical entries in href=3D"/xymon-cgi/svcstatus.sh?CLIENT=3Doracle1&SECTION=3Dmsgs:/var/lo= g/messages">/var/log/messages > &red Feb 8 10:14:25 oracle1 kernel: ip_tables: (C) 2000-2006 Netfilter Cor= e=20 > Team > &red Feb 8 10:14:25 oracle1 kernel: nf_conntrack version 0.5.0 (16384=20 > buckets, 65536 max) > &red Feb 8 10:14:25 oracle1 kernel: CONFIG_NF_CT_ACCT is deprecated and wi= ll=20 > be removed soon. Please use > &red Feb 8 10:14:25 oracle1 kernel: nf_conntrack.acct=3D1 kernel parameter= ,=20 > acct=3D1 nf_conntrack module option or > &red Feb 8 10:14:25 oracle1 kernel: sysctl net.netfilter.nf_conntrack_acct= =3D1=20 > to enable it. > >
> 
>
> 
> > > Full log href=3D"/xymon-cgi/svcstatus.sh?CLIENT=3Doracle1&SECTION=3Dmsgs:/var/lo= g/messages">/var/log/messages > Feb 8 10:14:25 oracle1 kernel: ip_tables: (C) 2000-2006 Netfilter Core Team > Feb 8 10:14:25 oracle1 kernel: nf_conntrack version 0.5.0 (16384 buckets, = > 65536 max) > Feb 8 10:14:25 oracle1 kernel: CONFIG_NF_CT_ACCT is deprecated and will be= =20 > removed soon. Please use > Feb 8 10:14:25 oracle1 kernel: nf_conntrack.acct=3D1 kernel parameter, acc= t=3D1=20 > nf_conntrack module option or > Feb 8 10:14:25 oracle1 kernel: sysctl net.netfilter.nf_conntrack_acct=3D1 = to=20 > enable it. > > > --===============2295095434469176878==--