I have rule that sends an email whenever a certain term is found in the syslog message. The rule works, and send alerts, when the syslog is from a Cisco device. But when a Juniper device sends that message, no alert is sent.
It's a very basic rule;
- SOURCE COMPUTERS - All source computers
- LOG ENTRIES - IF Message OR Contains abc
- TIME WINDOW - Filtering entries by time window is not set.
- ENTRY COUNT - Every matching entry fires the rule
- FLOOD PROTECTION - Flood protection is disabled.
- ACTIONS - ALERT INTEGRATION - When this rule fires, send a Log Rule Fired event to Orion Alerting.
Triggers on all Cisco devices, but my Juniper QFX5100 never causes a trigger.
In the Log Viewer, I can search for 'abc' and get results for all devices, Cisco and Juniper.
Anyone else have this issue? Or anyone have suggestions, or troubleshooting steps?
thanks