With a live search setup to watch for memory errors in Solaris I get multiple hosts answering for the Live Search. This is great, but what I need to happen is only show me a correct match when one server meets the search of 24 hits in 24 hours. Not when multiple hosts accumulative matches match 24 hits in 24 hours.
Ex. - I need to see when Tomah gets 24 hits in 24 hours not when Tomah and SanJose together get 24 hits in 24 hours.
Feb 25 13:52:43 tomah SUNW,UltraSPARC-III+: [ID 741384 kern.info] [AFT2] errID 0x007aed86.20d08e28 PA=0x000000d3.fe648e80
Feb 24 21:47:45 sanjose SUNW,UltraSPARC-III: [ID 314067 kern.info] [AFT0] errID 0x000a1dec.3f3c8f04 Corrected Memory Error on Slot C: J8001 is Persistent
The "ALERT" interface would need to offer multiple entries like this:
number of hosts = 1 AND number of events rises by 24.
Currently we only get number of hosts OR events OR sources rises by "x".