Log collection failure alerts | Online help - EventLog Analyzer

Log collection failure alerts

Device down alert:
 
When configured devices don't respond to pings from EventLog Analyzer, it implies either of the following:
  1. The selected Syslog devices are not sending logs to EventLog Analyzer.
  2. EventLog Analyzer has not collected logs from the Windows devices for the assigned interval time, triggering an alert to the configured email address.
For Windows devices, last scan time will be considered. On the other hand, last message time will be taken into account for Syslog devices. 

Note: The device down alert signals when the time lapsed since the last message exceeds the time interval set by the end user.

Low disk space alert:

Since EventLog Analyzer requires a minimum of 5GB of free space, an alert is generated and sent as an email notification to admins when the disk space available in the local directory, index directory, product database, or archive directory goes below 5GB. You can change this setting manually by navigating to Settings > Admin Settings > Product Settings > Product Notifications.

                  New to ADSelfService Plus?

                    • Related Articles

                    • How to set an alert notification for log collection failure

                      Objective This document will help you configure alert notification if log collection does not happen for a period of time for the devices added in EventLog Analyzer. Prerequisites You will need to have admin access to the EventLog Analyzer console. ...
                    • How to get notified about EventLog Analyzer's log collector failure

                      Objective EventLog Analyzer can send email alerts when the internal log collector service (SysEvtCol) crashes or stops unexpectedly. This alert helps administrators detect disruptions in core log ingestion and take immediate corrective action to ...
                    • Log import failure during remote log collection in EventLog Analyzer

                      Issue description EventLog Analyzer will display an error notification in the UI stating that the log import for selected files has failed. This issue will happen when EventLog Analyzer is unable to import a file during the scheduled log import ...
                    • Enabling historic log collection in EventLog Analyzer

                      EventLog Analyzer collects all the logs present in the Windows Event Viewer (i.e., Windows Logs > Application, Security, System) when the historic log collection option is enabled. To enable historic log collection, follow the steps below: Navigate ...
                    • Setting up alerts

                      How to: Hint on setting up alerts First, always check if any of the predefined alert criteria would satisfy the requirement. Proceed with custom alerts only if the requirement is very peculiar. Log on to GUI ⇾ Go to the "Alerts" tab ⇾ click on "Add ...