Announcement

Collapse
No announcement yet.

NSClient++ CheckEventLog not working

Collapse
X
 
  • Filter
  • Time
  • Show
Clear All
new posts

  • NSClient++ CheckEventLog not working

    hi,

    i read this thread, but if i try any of this commands (hostname replaced) i get everytime "CHECK_NRPE: Socket timeout after 10 seconds.".
    If i increase the timeout value, i get the same message, but after longer waiting time...
    Is there any tutorial or can someone help me to setup event log monitoring with centreon?

  • #2
    Hi

    Error is explicite: "Socket timeout after 10 seconds.".

    It's may be a network issue or a missing autorisation in nsci.ini configuration file. Please enable NSclient++ debug and check firwall

    ++
    Centreon Syslog Module Manager/Developper
    Centreon E2S Module Manager/Developper
    Centreon Enterprise Server (2.x / 3.x) : Centreon Engine 1.3.x / 1.4.x, Centreon Broker 2.6.x / 2.8.x , Centreon 2.x, Centreon-Syslog 1.5.x, Centreon E2S 2.0
    Nagios 3.x et NDOutil 1.x

    Comment


    • #3
      This can't be the problem, because i use NSClient and Check_nrpe for cpu/filesystem/service/.. checks and this works like a charm.
      Only the check -c CheckEventLog function don't work and throw this timeout error.

      --> when i install NSClient i only tick the checkbox "Enable common check plugins" can this be the mistake? (there are some other checkboxes like enable nsclient server/nrpe server/nsca client/wmi checks)
      Mr.Propper
      Junior Member
      Last edited by Mr.Propper; 9 April 2014, 16:21.

      Comment


      • #4
        Hi

        Do you run NSclient++ with LOCAL_SYSTEM user ? another user ? rights to access to EventLog are ok ?
        Centreon Syslog Module Manager/Developper
        Centreon E2S Module Manager/Developper
        Centreon Enterprise Server (2.x / 3.x) : Centreon Engine 1.3.x / 1.4.x, Centreon Broker 2.6.x / 2.8.x , Centreon 2.x, Centreon-Syslog 1.5.x, Centreon E2S 2.0
        Nagios 3.x et NDOutil 1.x

        Comment


        • #5
          The user have Administrator rights. If i login as this user i can browse to the eventlog without problems, so this can't be the problem.

          Comment


          • #6
            I have fixxed the most of my problems, but one new comes around...

            ./check_nrpe -H 192.168.2.121 -p 5666 -c CheckEventLog -a truncate=1023 MaxWarn=1 MaxCrit=1 file='Application' filter=in "filter=(generated > -5m) AND (type NOT IN ('info'))" descriptions unique syntax='(Severity of: %severity%) (type of: %type%) (Logged at: %written%) %message%'

            give me the error "Exception processing request: Request command contained illegal metachars!" --> ???
            Mr.Propper
            Junior Member
            Last edited by Mr.Propper; 11 April 2014, 15:50.

            Comment


            • #7
              I found the mistake. I've to change allow nasty characters.

              But the output of "./check_nrpe -H 192.168.2.121 -p 5666 -c CheckEventLog -a file=system MaxWarn=10 MaxCrit=20" is not what i expected.
              I only want the important part of the system log --> only critical erros or warnings if there are more than 5-10 in the last 1h if thats possible...

              Please help me with the commandds.

              Comment

              Working...
              X