Documentation:
3.2.2
Create an event type based on a field via eventtypes.conf. For example:
[$NAME %$FIELD%] $SEARCH_QUERY
Event type templates works a lot like macro searches: %$FIELD% gets filled in at search time with field=foo or field=bar, etc -- whatever the search query yields for that event type's field.
ConfigurationWhen setting the name in eventtypes.conf, follow these specifications:
[$EVENTTYPE]
[cisco-%code%] cisco
If "code=432", this event type becomes "cisco-432".
Comments
No comments have been submitted.