In its broadest sense, learning can be defined as a process of progressive change from ignorance to knowledge, and from indifference to understanding....

log监控工具swatch

上一篇 / 下一篇  2008-03-13 22:42:08 / 个人分类:Unix & Linux

安装:
perl Makefile.PL
make
make test
make install

配置:
.swatchrc
配置文件是用来告诉Swatch哪些事件需要想用户报告,采用什么样的方式通知用户。
watchfor / / 监控设定字段
echo[=mode] 输出报刊匹配模式的行,缺省为normal。
bell[=n] 在终端振铃n次
mail[=address:address:…] 指定邮件发送的email地址,多个地址间用"":"隔开
throttle=options 限制匹配行的动作。
exec=command 模式匹配时,执行command命令。

配置文件示例如下:

watchfor /ftp/
echo red
mail addresses=xhl\@company.com,subject=Syslog Monitor Alert
 
watchfor /eth/
echo red
mail addresses=xhl\@company.com,subject=Syslog Monitor Alert
 
watchfor /error/
echo red
mail addresses=xhl\@company.com,subject=Syslog Monitor Alert
 
watchfor /failed/
echo red
mail addresses=xhl\@company.com,subject=Syslog Monitor Alert
 
watchfor /file system full/
echo red
mail addresses=xhl\@company.com,subject=Syslog Monitor Alert
 
watchfor /vmunix/
echo red
mail addresses=xhl\@company.com,subject=Syslog Monitor Alert
 
# Kernel problems or system reboots
watchfor        /panic|halt/
echo red
mail addresses=xhl\@company.com,subject=Syslog Monitor Alert

执行:
swatch -c ~/.swatchrc -t /var/log/messages

e4node1:~ # swatch -c ~/.swatchrc -t /var/log/messages
 
*** swatch version 3.1.1 (pid:17163) started at Wed Mar 19 15:20:16 CST 2008
 
Mar 19 17:13:47 e4node1 kernel: cdrom: open failed.
Mar 19 17:13:47 e4node1 kernel: cdrom: open failed.
Mar 19 17:13:47 e4node1 kernel: end_request: I/O error, dev fd0, sector 0
Mar 19 17:13:47 e4node1 kernel: end_request: I/O error, dev fd0, sector 0
Mar 19 17:13:47 e4node1 kernel: end_request: I/O error, dev fd0, sector 0



Swatch是一个很好的日志文件管理工具,它能确实的保证你的日志文件的完整性,配合syslog server 一起用,可实时的监控你所管理的各台机器系统的问题。


TAG:

 

评分:0

我来说两句

显示全部

:loveliness: :handshake :victory: :funk: :time: :kiss: :call: :hug: :lol :'( :Q :L ;P :$ :P :o :@ :D :( :)

日历

« 2008-12-03  
 123456
78910111213
14151617181920
21222324252627
28293031   

数据统计

  • 访问量: 6793
  • 日志数: 928
  • 影音数: 2
  • 文件数: 2
  • 书签数: 3
  • 建立时间: 2008-02-17
  • 更新时间: 2008-12-02

RSS订阅

Open Toolbar