- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Problems with custom event source alerting???
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Hi CIETCSecops,
I have seen a similar problem in the past with custom events that I've configured. The situation with my events was that although I believed all the messages were parsing, they were all being recorded as undefined.
You can see if the messages are being defined by clicking on the Analysis tab, expand Graph View and select "Events by Event Type".
Then in the right hand window select "Display Advanced Graph Options" and select "Event Categories" under the Data Type selection box.
Apply the filters in the top section selecting your custom event type from the dropdown list and select a large enough timeframe to ensure that messages have been received.
When you click the "Update Now" button you will see a graph displaying what categories the messages are being parsed into. If the only category displayed is "Undefined" then the messages are not parsing.
I would start there and then update this post with your findings, maybe we can find the solution.
Good Luck,
Steve
