Unix log file monitoring tests correctly, but does not generate an alert?

Bixby 101 Reputation points
2021-09-01T20:25:16.597+00:00

We are running SCOM 2019 UR2

I'm using the MS documentation to create a logfile monitor for Unix/Linux servers. -
https://learn.microsoft.com/en-us/system-center/scom/unix-linux-logfile?view=sc-om-2019

I created the monitor and successfully tested for the text, "Error". The test shows a green check as successful.
Our Linux admins even check the log and there are instances of the word "error" in the log.

But for some reason SCOM never creates an alert?

The Linux admins even cleared the log, created a new "error", and still no alert?

I applied the monitor to a single server and it did not work. I even created a group, added the single server to the group, applied the group to the monitor and still no alert?

I must me doing something wrong.

has anyone experienced this issue and if so, what was your fix? Any suggestions as to what I am doing wrong?

Thank you in advance for any assistance with this frustrating instance.

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,446 questions
{count} votes

Accepted answer
  1. AlexZhu-MSFT 5,626 Reputation points Microsoft Vendor
    2021-09-02T02:08:53.66+00:00

    Hi,

    The UNIX/Linux log file monitor cannot handle wildcards. The log file name must be fixed, that is, we can only monitor a single file. Do we monitor multiple files, if so, it may not work.

    The monitors created from out-of-box template have the following limitations and we may check if all the conditions are met.

    It only works well with certain behavior of the log file
    It only works with one log file
    It doesn't actually suppress alerts corresponding to entries logged during maintenance mode; the alerts come anyhow soon after maintenance window ends

    Alex
    If the response is helpful, please click "Accept Answer" and upvote it.


0 additional answers

Sort by: Most helpful