+1
0
-1
1
answer

Feature request: om_email

Botond,

Would you consider creating an output module for email? It would be quite useful for generating alerts. While one can use exec_async to send email, it is rather cludgy. 

Cheers

 

Ash

AskedDecember 30, 2014 - 8:22pm
+1
1
-1
1
answer

Counter tracking assistance

I have multiple windows hosts sending events in binary to a single tcp listener.<Input windows>
    Module     im_tcp
    Port       9999
    Host       0.0.0.0
    InputType  Binary

I am trying to track the rate of logs from the servers and create email alerts when the rate either drops or crosses a high watermark per hour. 

To do that I need to create a stat / variable appending the hostname and hourstamp such as

AskedDecember 19, 2014 - 5:54pm
+1
1
-1
1
answer

im_file configuration

i defined an input for im_file that is being sent as syslog

i have multiple files in a folder what i want to do is read each file and on EOF copy to another folder.

didn`t find the option to identify EOF

AskedDecember 18, 2014 - 4:22pm

Pages