<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Using a Generic Text Log rule to monitor an ASCII text file – even when the file is a UNC path</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx</link><description>There are several examples in blogs on how to create a generic text log rule to monitor for a local text file (Unicode, ASCII, or UTF8). This will be a step-by-step example of doing the same, however, using this to monitor the log file on a remote UNC</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Using a Generic Text Log rule to monitor an ASCII text file – even when the file is a UNC path</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx#3257060</link><pubDate>Sat, 20 Jun 2009 12:37:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3257060</guid><dc:creator>RogerM</dc:creator><description>&lt;p&gt;Excellent example, thanks!&lt;/p&gt;
&lt;p&gt;One comment on Alert Supression though.&lt;/p&gt;
&lt;p&gt;Does not Parameter 1 equal Params/Param[1] (the entire line)?&lt;/p&gt;
&lt;p&gt;If so, for alert supression to work, the line would have to be exactly the same. A date or timestamp will prevent supression to happen.&lt;/p&gt;
&lt;p&gt;Regards&lt;/p&gt;
&lt;p&gt;Roger&lt;/p&gt;
</description></item><item><title>re: Using a Generic Text Log rule to monitor an ASCII text file – even when the file is a UNC path</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx#3257113</link><pubDate>Sat, 20 Jun 2009 22:22:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3257113</guid><dc:creator>Lee Nicoll</dc:creator><description>&lt;p&gt;Nice work. Quick question. Does the SCOM Agent on th Watcher node need to be running under a Network account?&lt;/p&gt;
</description></item><item><title>re: Alert Supression</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx#3257114</link><pubDate>Sat, 20 Jun 2009 22:30:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3257114</guid><dc:creator>kevinhol</dc:creator><description>&lt;p&gt;&amp;quot;One comment on Alert Supression though.&lt;/p&gt;
&lt;p&gt;Does not Parameter 1 equal Params/Param[1] (the entire line)?&lt;/p&gt;
&lt;p&gt;If so, for alert supression to work, the line would have to be exactly the same. A date or timestamp will prevent supression to happen.&amp;quot;&lt;/p&gt;
&lt;p&gt;-------------------&lt;/p&gt;
&lt;p&gt;Yes - Parameter 1 equals that - therefore - my example would supress anytime the line that matched was identical. &amp;nbsp;Typically - this is correct. &amp;nbsp;If the line isnt identical - then it will be a different alert. &amp;nbsp;If that is not desirable - then remove Param 1.&lt;/p&gt;
</description></item><item><title>re: Network Account?</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx#3257116</link><pubDate>Sat, 20 Jun 2009 22:32:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3257116</guid><dc:creator>kevinhol</dc:creator><description>&lt;p&gt;No - in my example - I used an agent using Local System.... which is an &amp;quot;Authenticated User&amp;quot; and therefore had access to this share. &amp;nbsp;THis specific share had share permissions of Everyone-FullControl, and NTFS permissions of Everyone-Read.&lt;/p&gt;
&lt;p&gt;If your share or NTFS permissions are more strict - then make sure you grant the computer account of the agent access to both share and NTFS, or run the agent under a domain user account, which has access to the share/NTFS.&lt;/p&gt;
</description></item><item><title>re: Using a Generic Text Log rule to monitor an ASCII text file – even when the file is a UNC path</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx#3265536</link><pubDate>Fri, 17 Jul 2009 05:16:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3265536</guid><dc:creator>Desmond</dc:creator><description>&lt;p&gt;Nice work. Just curious. Is it possible to set the Rule Target to specific machine/server rather than a class of machines?&lt;/p&gt;
</description></item><item><title>re: Targeting</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx#3265767</link><pubDate>Fri, 17 Jul 2009 20:39:04 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3265767</guid><dc:creator>kevinhol</dc:creator><description>&lt;p&gt;Yes and No.&lt;/p&gt;
&lt;p&gt;A rule/monitor workflow MUST target a class. &amp;nbsp;Period. &amp;nbsp;End of story.&lt;/p&gt;
&lt;p&gt;However - we have two options here:&lt;/p&gt;
&lt;p&gt;1. &amp;nbsp;Target a generic class, like Windows Operating System - then disabled, then override as enabled for my one specific object. &amp;nbsp;This is the example I used above.&lt;/p&gt;
&lt;p&gt;2. &amp;nbsp;Create a new class, using WMI/Registry provider for example, and make only the one special computer I want to be a discovered instance of that class... then target that class (much more complicated)&lt;/p&gt;
</description></item><item><title>re: Using a Generic Text Log rule to monitor an ASCII text file – even when the file is a UNC path</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx#3276241</link><pubDate>Mon, 24 Aug 2009 10:20:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3276241</guid><dc:creator>Richard</dc:creator><description>&lt;p&gt;Excellent post, although I am having one strange problem, the log reader works 100% and the alerts are correct, but the system seems to randomly alert off the same line in the log file over and over again, what could I have done wrong to get this happening?&lt;/p&gt;
</description></item><item><title>re: Using a Generic Text Log rule to monitor an ASCII text file – even when the file is a UNC path</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx#3277340</link><pubDate>Thu, 27 Aug 2009 09:10:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3277340</guid><dc:creator>Babu</dc:creator><description>&lt;p&gt;i got error for the path &amp;quot;C:\SummitCfAdapter\PROD\SummitCfAdapter-LOH-PROD\log\SummitCfAdapterMaster.log&amp;quot; Error opening log file directory Event ID's 31705,31707&lt;/p&gt;
&lt;p&gt;Please help&lt;/p&gt;
</description></item><item><title>re: errors</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx#3277341</link><pubDate>Thu, 27 Aug 2009 09:13:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3277341</guid><dc:creator>kevinhol</dc:creator><description>&lt;p&gt;Please post more details from the events you are getting - I dont know what those event ID's are.&lt;/p&gt;
</description></item><item><title>re: Using a Generic Text Log rule to monitor an ASCII text file – even when the file is a UNC path</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx#3277342</link><pubDate>Thu, 27 Aug 2009 09:16:27 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3277342</guid><dc:creator>Babu</dc:creator><description>&lt;p&gt;i got error for the path &amp;quot;C:\SummitCfAdapter\PROD\SummitCfAdapter-LOH-PROD\log\SummitCfAdapterMaster.log&amp;quot; Error opening log file directory Event ID's 31705,31707&lt;/p&gt;
&lt;p&gt;Error description&lt;/p&gt;
&lt;p&gt;&amp;quot;Error opening log file directory&lt;/p&gt;
&lt;p&gt; Directory = &lt;/p&gt;
&lt;p&gt; C:\SummitCfAdapter\PROD\SummitCfAdapter-LOH-PROD\log&lt;/p&gt;
&lt;p&gt;Error: 0x80070003 &lt;/p&gt;
&lt;p&gt;Details: The system cannot find the path specified.&amp;quot;&lt;/p&gt;
&lt;p&gt;but when I change path to &amp;quot;C:\SummitCfAdapter\PROD&amp;quot; it works fine.&lt;/p&gt;
&lt;p&gt;is it because of &amp;quot;-&amp;quot; in the file path.&lt;/p&gt;
&lt;p&gt;I'hv tried enclosing path in the double and single quote also but the got error &amp;quot;The filename, directory name, or volume label syntax is incorrect.&amp;quot;&lt;/p&gt;
</description></item><item><title>re: Using a Generic Text Log rule to monitor an ASCII text file – even when the file is a UNC path</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx#3277367</link><pubDate>Thu, 27 Aug 2009 10:58:24 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3277367</guid><dc:creator>Babu</dc:creator><description>&lt;p&gt;thanks kevin for your quick reply. Dont know how but it is working now. not changed anything just restarted the health service and it is working.&lt;/p&gt;
</description></item><item><title>re: Using a Generic Text Log rule to monitor an ASCII text file – even when the file is a UNC path</title><link>http://blogs.technet.com/kevinholman/archive/2009/06/20/using-a-generic-text-log-rule-to-monitor-an-ascii-text-file-even-when-the-file-is-a-unc-path.aspx#3284732</link><pubDate>Sun, 04 Oct 2009 12:08:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3284732</guid><dc:creator>VRKumar</dc:creator><description>&lt;p&gt;Thanks Kevin for the excellent example.&lt;/p&gt;
&lt;p&gt;i have a problem as i fallowed excatly the steps you mentioned but it is not giving me any output.&lt;/p&gt;
&lt;p&gt;the path i tried 2 ways &lt;/p&gt;
&lt;p&gt;\\localhost\d$\product&lt;/p&gt;
&lt;p&gt;&amp;amp;&lt;/p&gt;
&lt;p&gt;d:\product\&lt;/p&gt;
&lt;p&gt;file name is company.log&lt;/p&gt;
&lt;p&gt;is their a way to find if the rule is working or not?????&lt;/p&gt;
&lt;p&gt;-VRKumar&lt;/p&gt;
</description></item></channel></rss>