Documentation forOrion Platform

Create custom log-processing rules

This Orion Platform topic applies only to the following products:

NCMNPMSAMUDTVMAN

On the Log Processing Configuration page, you can create custom rules to complement the standard, out-of-the-box rule sets. You can define rule conditions to identify a specific log entry, and then establish subsequent actions, such as executing commands and discarding log entries.

The pre-defined Rule Policy groups organize rule policies based on the message source and determine the rule policy evaluation order. The Processing Policies pane is organized into the following policy groups:

  • Log Files (Log Analyzer only)
  • Syslog
  • Traps
  • VMware Events
  • Windows Events (Log Analyzer only)
  • Global Pre-processing: Evaluated before log-specific and global post-processing rule policies
  • Global Post-processing: Evaluated after all log-specific rule policies
Group Message Type Evaluation Order
Global Pre-processing All messages Evaluated first
Log Files (Log Analyzer only) Windows flat file messages Evaluated after items in the pre-processing group. Although the items are ordered alphabetically, they run independently, at the same time. You can see the execution order in the rules list.
Syslog Syslog messages
Traps Trap messages
VMware Events VMware event messages
Windows Events (Log Analyzer only) Windows event messages
Global Post-processing All messages Evaluated last
  1. On the Log Viewer toolbar, click Settings.

  2. In the Processing Policies pane, click to expand a policy group, and then click My Custom Rules.

  3. Click Create New Rule.

  4. Enter a descriptive name for the rule, and then click Next.

  5. Select your source computers.

    You can choose to trigger this alert from all sources, or specify conditions and values for one or more sources.

  6. Define your log entry rule conditions and values, and then click Next.

    The log entry conditions vary by log source type. In the example below, an incoming SNMP Trap message meeting specified Varbind element with OID and name criteria will trigger the designated alert action.

    Specify the time when the rule will be active. The default value is always active.

    Specify the entry threshold to trigger the rule. The default value is for every matching entry.

    Specify how much time to prevent rule from firing for flood protection. The default value is no cooldown time.

  7. Select one or more log entry actions.

  8. Integrate an alert action, and then click Next.

  9. Review your rule summary, and then click Save to create the rule. To edit your rule conditions and actions, click Back.

  10. After you create one or more rules, you can then edit, enable, or disable each rule.

  11. To return to the Log Viewer, navigate to My Dashboards > Logs > Log Viewer.

Add custom rule actions

You can add one or more of the following actions to any custom rule:

  • Forward the entry: Send the entry to another system for further processing.

  • Run an external program.

    1. In the Rule Actions pane, click Add an Action.

    2. Select Run an External Program, and then click Configure Action.

    3. Enter the program to run, command line arguments (optional), account for execution, and then click Done.

    4. Custom Windows accounts can be used for external program execution that uses Orion's Windows credentials. Click the drop-down menu to refresh if changes are made to Windows credentials.

      Find a list of external program variables here.

  • Flag for discard: The log entry is not saved to the database, but subsequent rule actions are still applied.

  • Stop processing rules: Stops additional rule processing for the active log entry.