The current set up that we are trialling is using a Snare agent to forward messages from log files to Kiwi. This works fine and has allowed us to alert from the inputs passed to Kiwi.
DataSynapse provides the option of sending SNMP messages and I'm currently testing the feasibility of this. The SNMP messages reach Kiwi and I can see the messages being received.
The problem that I am having is that when creating a rule that will send me an email when it finds a SNMP message, I filtered by input source. This doesn't seem to work? If I send a test SNMP message then the rule is triggered and the action executed.
Any thoughts or help much appreciated.
Thanks,
Mike