11 Oct
2013
11 Oct
'13
4:57 p.m.
On 10/11/2013 4:46 AM, Bakkies Gatvol wrote:
I have this and it is good
CLASS=linux PROC ntpd PROC sshd 1 PROC cron FILE /var/log/messages red MODE=644 LOG /var/log/messages %panic|error|Critical LOAD 25.0 35.0
except for the splunk server
Check in analysis.cfg.5.html under the section: "RULES: APPLYING SETTINGS TO SELECTED HOSTS"
HOST=%.*.foo.com LOAD 7.0 12.0 HOST=bax.foo.com LOAD 3.0 8.0will result in the load-limits being 7.0/12.0 for the "bax.foo.com" host, and 3.0/8.0 for all other foo.com hosts.
I suspect the same option is available on LOG
-- Do things because you should, not just because you can.
John Thurston 907-465-8591 John.Thurston at alaska.gov Enterprise Technology Services Department of Administration State of Alaska