3 Replies Latest reply on Feb 23, 2010 4:06 PM by cmga

    Syslog filter not working

      Hi all,

      I have NPM 9.5 installed and using Event Log Forwarder on Blackberry Enterprise Server to capture all Warnings/Errors and forward to the Syslog on NPM server.

      Since pretty much all BES events use the EventID 20000, I need to be able to filter the results in Syslog rather than in the forwarder.

      I have tried to enter this filter to discard the events, however it's not working. Can somebody please help?

      Event 20000

      Feb 22 08:16:08 BESSVR01 MSWinEventLog 4 Application 510 Mon Feb 22 08:16:08 2010 20000 BlackBerry Messaging Agent BESSVR01 Agent 1 N/A Warning BESSVR01 0 Failed to create XHTML body, using raw HTML

      In the Syslog, on the Message tab, I am entering *using raw HTML* in the 'Syslog Message Pattern' field, however the above event is still being logged and emailed to me. I have tried *Failed to create XHTML body, using raw HTML*, but the same happens. The alert action I have set for this filter rule is 'Discard Syslog Message'.

      This is just one example. Many other filters are not working, because of the same reason. Is something wrong with the message pattern I am using?

      Another is:

      Feb 19 11:11:04 BESSVR01 MSWinEventLog 4 Application 399 Fri Feb 19 11:11:04 2010 20000 BlackBerry Messaging Agent BESSVR01 Agent 1 N/A Warning BESSVR01 0 Failed to do progressive image conversion: RES_UnsupportedImageType (1)

       

      Filter message pattern is *RES_UnsupportedImageType*, but still the message gets logged.

      Any ideas?