HP MSR2000/3000/4000 Router Series Network Management and Monitoring Command Reference

266
event syslog
Use event syslog to configure a Syslog event for a CLI-defined monitor policy.
Use undo event to delete the event in a CLI-defined monitor policy.
Syntax
event syslog priority level msg msg-body occurs times period period
undo event
Default
No log event is configured.
Views
CLI-defined policy view
Predefined user roles
network-admin
Parameters
priority level: Specifies the lowest severity level for matching log messages. The level argument can be an
integer in the range of 0 to 7, or the word all, which represents any severity level from 0 to 7. A lower
number represents higher priority level. For example, specify a severity level of 3 to match log messages
from level 3 to level 0.
msg msg-body: Specifies a regular expression to match the message body, a string of 1 to 255
characters. For more information about regular expressions, see Fundamentals Configuration Guide.
occurs times period period: Executes the policy if the number of log matches over an interval exceeds the
limit. The times argument specifies the maximum number of log matches in the range of 1 to 32. The
period argument specifies an interval in the range of 1 to 4294967295 seconds.
Usage guidelines
Use Syslog event monitor policies to monitor log messages.
EAA executes a Syslog event monitor policy when the number of matching logs over an interval reaches
the limit.
NOTE:
EAA does not count log messages generated by the RTM module when it counts log matches.
You can configure only one event for one monitor policy. If the monitor policy already contains an event,
the new event replaces the old event.
Examples
# Configure a CLI-defined policy to monitor Syslog messages for level 3 to level 0 messages that contain
the down string. Enable the system to execute the policy when five log matches are found within 6
seconds.
<Sysname> system-view
[Sysname] rtm cli-policy syslog
[Sysname-rtm-syslog] event syslog priority 3 msg down occurs 5 period 6