This discussion has been locked. The information referenced herein may be inaccurate due to age, software updates, or external references.
You can no longer post new replies to this discussion. If you have a similar question you can start a new discussion in this forum.

Kiwi Syslog Email Alerts & Filters

Hi all,

I just have some questions around setting up email alerts and filters in Kiwi Syslog.

  1. What is the average processing time from receiving a syslog message to it being processed and emailed out? I'm seeing delays of up to 30 seconds or more before I am even seeing it in the email log within Kiwi, then you add the time it takes for your mail server to actually deliver the message. Curious to see what others are seeing?
  2. When creating filters and actions within a rule, the filters look to be processed as "AND" instead of "OR". E.g. If I have a single rule called "Logon Success Events", with an action to email the alert, and a filter to catch the first devices message which might be "logon successful" and the second devices message "successful logon", it appears to not work. It appears I have to create a new rule for each different message string? Is there a way for multiple filters under a rule to be processed as "OR" and not "AND"?

Many thanks!

  • To answer both questions:

    1. Kiwi Syslog relays email through the specified SMTP server.  I would check to see how quickly they are being processed on the mail server side.

    2. The filters do use an AND, and not an OR.  You could try a RegEx value the contains logon