There were no changes made to the ipMonitor Event Log Monitor between version 8 and 9. As a result, the following ipMonitor 8 article is also valid for ipMonitor 9:
There are currently 3 different options within this Monitor:
- Combine up to 15 Found Scenarios into one Alert: 15 individual Information Alerts will be folded or merged into a single Alert. This is ideal for Events such as Information types that are apt to generate many of the same Events.
- Disabled - Send up to 5 Information Alerts (Individually): Refers to the "fold" feature. This option will send up to a maximum of five Information Alerts, one for each matching entry that is located. This is ideal for Events such as Application Errors.
- Disabled - Send first Found Scenario: Sends a single Information Alert for each Monitor test, regardless of how many matching entries are located. Only the first matching entry will trigger an Information Alert. This is ideal for Events such as Security, when you want to be informed immediately or take immediate action.
All options will send you a notification if one or more matches are found.
One thing to keep in mind is that the Monitor does not fail when it finds a match. The only time it will fail is if it cannot read the event log. That is when the "Accumulated Failures per Alert" is observed.
Do let me know if you have any additional questions regarding this.
Chris Foley - SolarWinds - Support Specialist
Support: 866.530.8040 | Fax: 512.857.0125
network management simplified | solarwinds.com