Adding and Editing a Syslog Monitor
To add or edit a Syslog monitor:
- Click the tab, then click . The Monitor Library dialog appears.
- Click the tab. The Passive Monitor list appears.
- Click and select from the list to create a new Syslog monitor. Click .
- or -
Select the Syslog monitor you want to change from the list of current monitors, and then click . - Type or select the appropriate information in the following fields.
- . Type a name for the monitor. This name displays in the Passive Monitor Library.
- . Type a short description for the monitor. This description displays next to the monitor in the Passive Monitor Library.
- . You can click the button to access the expression editor, where you can create your expression, test it, and compare it against potential payloads you can receive. After creating the expression, click to insert that string into the Match on box.
: If you have multiple payload "match on" expressions, they are linked by "OR" logic - not "AND" logic. Example: If you have two expressions, one set to "AB" and the other to "BA", it will match against a trap containing any of the following: "AB" or "BA" or "ABBA".
- Click to list this event in the Passive Monitor Library as a Syslog Passive Monitor.
After configuring a passive monitor in the Passive Monitor Library, add the monitor to devices.
For an example of why you might create a Syslog Event, see Sample of a Syslog Monitor Event.