 |
| Senior Member |
 |
Joined: Wed Sep 01, 2010 9:46 pm Posts: 372 Location: USA
Certs: CCNA R&S/Security, IPS Specialist, 642-642
|
|
The community recently had a few discussions related to syslog collectors, which got me thinking about what messages to create alerts on.
In the past, I've browsed the history of log data from certain devices to identify messages that need alerts. That method works well for the more common messages, but what about log messages that haven't been seen before because they occur only in rare events? It seems the most important alerts would be for log messages I might not have seen before.
How do you guys handle this? Do you create generic alerts for all messages with a certain level or higher? Do you browse through a list of all possible messages to pick out what seems important?
|
|