I need help with syslog alerts. I've created a syslog alert that basically alerts our group when there is a warning of error in the Windows event log and this seems to work ok. I would like to create a 2nd alert for specifics, such as when a warning or error from 2 specific servers and when the message contains "Websense" of "WBS" and then send the alert to a specfic email address.
If I disable the 1st alert it seems to work but it will not work as long as the 1st alert is enabled. I do have other alerts that seem to work which are for different types of errors. It seems as if Orion will only send the 1st alert and not the 2nd id they are related.
Any suggestions would be very much appreciated......