New Question
 
 
PRTG Network Monitor

Intuitive to Use.
Easy to manage.

300.000 administrators have chosen PRTG to monitor their network. Find out how you can reduce cost, increase QoS and ease planning, as well.

Free PRTG
Download >>

 

What is this?

This knowledgebase contains questions and answers about PRTG Network Monitor and network monitoring in general. You are invited to get involved by asking and answering questions!

Learn more

 

Top Tags


View all Tags


How can I monitor and gets alerts when an event log entry happens?

Votes:

0

Your Vote:

Up

Down

I have tried setting up and searched the KB for information on how to setup event log monitoring. What I am trying to do is get Email alerts when specific event logs show up. Can you please let me know how to do this? I have the WMI event log setup for the one I want and it is showing green, however that event log I am monitoring is in the log and should be red but it is green.

email event-log wmi

Created on Dec 14, 2010 11:22:03 PM by  ThorinOak (2) 1



13 Replies

Votes:

0

Your Vote:

Up

Down

Created on Dec 15, 2010 11:10:34 AM by  Aurelio Lombardi [Paessler Support]

Last change on May 28, 2014 1:23:13 PM by  Gerald Schoch [Paessler Support]



Votes:

0

Your Vote:

Up

Down

I also setup event log checking with the API. My question however is how specifically do I get it to send me an alert with the event log shows up? I checked the notification and channel tab but I would like specific instructions please.

Created on Dec 15, 2010 4:07:31 PM by  ThorinOak (2) 1



Votes:

0

Your Vote:

Up

Down

Basically one would setup the sensor (with matching filters if necessary, for Event ID, etc.) and then either use Warning- and/or Error-Limits to set the sensor into warning/error-state every time the event occurs (and then use a state-trigger with this). Or you can also use the Change-Trigger.

Created on Dec 15, 2010 4:46:50 PM by  Torsten Lindner [Paessler Support]



Votes:

0

Your Vote:

Up

Down

But the WMI event log never gets into an error or warning state.

It's counting matching event entries and shows them in the volume channel. Yes I can set a notification, when the value changes, but it will never get in an error state.

Created on Aug 12, 2011 8:15:05 AM by  Klaus-Dieter Gundermann (0) 1



Votes:

0

Your Vote:

Up

Down

Dear Klaus-Dieter, have you set the Error-/Warning-Limits? If so, to which values?

Created on Aug 12, 2011 12:07:07 PM by  Torsten Lindner [Paessler Support]



Votes:

0

Your Vote:

Up

Down

Where should I set them? The wmieventlogsensor has no configuration options for Error-/Warning Limits.

Created on Aug 12, 2011 3:10:20 PM by  Klaus-Dieter Gundermann (0) 1



Votes:

0

Your Vote:

Up

Down

These Limits are to be set on the Channels-Tab, and of course the WMI Event Log Sensor does have them as well.

Created on Aug 12, 2011 4:17:38 PM by  Torsten Lindner [Paessler Support]

Last change on May 28, 2014 1:24:01 PM by  Gerald Schoch [Paessler Support]



Votes:

0

Your Vote:

Up

Down

Hi, it's an old case but i have a problem too with the WMI Eventlog Sensor.

I setup WMI Eventlog sensor and the Upper Error Limit to 8 on the New Records Channel. No Upper Warning Limit set yet. In the notification settings i set the Down state and latency to 2 s.

when i now generate the Event ID on the monitored server the status of the sensor changed not to down so i never receive an notification.

for testing is use the Event ID 4625 Logon Failure and generate the failer with a simple net use command.

Created on Aug 29, 2011 8:25:00 PM by  dvi (-2) 1



Votes:

0

Your Vote:

Up

Down

Hello, I'm afraid any numbers higher than 0 don't work with the Eventlog Sensors and Error/Warning-Limits on them, because these limits refer to the speed-values of the Eventlog Sensor (i.e. 8 Events per second), and these are very often between 0 and 1.

Created on Aug 30, 2011 2:21:22 PM by  Torsten Lindner [Paessler Support]



Votes:

0

Your Vote:

Up

Down

Hi, I've ended 0 as upper warning limit. In the detail view, I can see the graph turns red. but under device view, it is still green. I'm wondering why it is not warning status is not reflected in Device view and Warning sensors view?

Thanks

Created on Jul 25, 2013 10:54:26 PM by  LeoRX (0) 1



Votes:

0

Your Vote:

Up

Down

Very often this happens with Eventlog sensors, because they only show the error state for one scan (when error-limits are used), and then go into UP/Green state with the next scan again, because the event is not again found. It's better to work with Change-Triggers on Eventlog- Sensors actually. They will notify each time an event is found.

Created on Jul 26, 2013 12:27:35 PM by  Torsten Lindner [Paessler Support]



Votes:

0

Your Vote:

Up

Down

Hello!

Can one of suggested Sensors filter Windows Log events by Event Level (Critical, Warning, Error)? Can't find this filter in any of Sensors.

Created on Jan 23, 2020 2:24:02 PM by  Vasiliy (46) 1



Votes:

0

Your Vote:

Up

Down

Hi Vasily,

It seems that there is currently no filter option for "Critical". You can find all other filters in the settings of the Windows API Event Log and the WMI Event Log Sensor.


Kind regards,
Birk Guttmann, Tech Support Team

Created on Jan 24, 2020 10:01:45 AM by  Birk Guttmann [Paessler Support]



Please log in or register to enter your reply.


Disclaimer: The information in the Paessler Knowledge Base comes without warranty of any kind. Use at your own risk. Before applying any instructions please exercise proper system administrator housekeeping. You must make sure that a proper backup of all your data is available.