On 10/11/2013 4:46 AM, Bakkies Gatvol wrote:
I have this and it is good
CLASS=linux
PROC ntpd
PROC sshd 1
PROC cron
FILE /var/log/messages red MODE=644
LOG /var/log/messages %panic|error|Critical
LOAD 25.0 35.0
except for the splunk server
Check in analysis.cfg.5.html under the section:
"RULES: APPLYING SETTINGS TO SELECTED HOSTS"
HOST=%.*.foo.com
LOAD 7.0 12.0 HOST=bax.foo.com
LOAD 3.0 8.0
will result in the load-limits being 7.0/12.0 for the "bax.foo.com" host, and 3.0/8.0 for all other foo.com hosts.
I suspect the same option is available on LOG
--
Do things because you should, not just because you can.
John Thurston XXX-XXX-XXXX
user-ce4d79d99bab@xymon.invalid
Enterprise Technology Services
Department of Administration
State of Alaska