Hi,
Thanks, it seems that i miss a point in the command line.
But when i try :
earliest=-24h index="nagios" nagiosevent="CURRENT HOST STATE" | rex ".+CURRENT HOST STATE: (?P [^;]*)(?=;)"| stats count by device
I got no elements but when i search :
earliest=-24h index="nagios" nagiosevent="SERVICE ALERT" | rex ".+SERVICE ALERT: (?P [^;]*)(?=;)"| stats count by device
I got the device list.
In fact when i search :
earliest=-24h index="nagios" sourcetype=nagios
I got a lot of information but in the "nagiosevent" i just got 4 elements :
SERVICE ALERT
SERVICE NOTIFICATION
GLOBAL SERVICE EVENT HANDLER
SERVICE EVENT HANDLER
But if i read you well i should have "CURRENT HOST STATE" at midnight ?
An example of what i got now :
1323164934 src_host="SERVER001" perfdata="SERVICEPERFDATA" name="FTP" severity="OK" attempt="1" statetype="HARD" executiontime="0.016" latency="0.216" reason="FTP OK - 0,005 second response time on port 21 [220 Welcome to FTP service.]" result="time=0,004622s;;;0,000000;10,000000"
host=SERVER003 Options| sourcetype=nagiosserviceperf Options| source=/srv/eyesofnetwork/nagios/var/log/service-perfdata Options| src_host=BALWPDMZ001 Options
2
12/6/11
10:48:54.000 AM
1323164934 src_host="SERVER002" perfdata="SERVICEPERFDATA" name="SERVICE_BACKUPEXEC_AGENT" severity="OK" attempt="1" statetype="HARD" executiontime="0.275" latency="0.187" reason="OK: Backup Exec Agent Br
... View more