What is the best practice to monitor Logs. Either using check_logfiles or for that matter any other.
I will describe the problem
- Server X - Monitoring Log - For Pattern “A, B …n” number of patterns - using single service
There is a event manager which is pulling events from icinga and creating alerts and tickets
The problem is after the first event is raised - the next polling cycle if there is no more errors in the log it closes in Icinga. This triggers OK state for the service and the alert gets closed in event manager before even the technician can see. We do not want to raise a OK event for this service. How to not change State immediately in the next polling cycle.