Mar 20 2022
10:44 AM
- last edited on
Apr 08 2022
11:02 AM
by
TechCommunityAP
Mar 20 2022
10:44 AM
- last edited on
Apr 08 2022
11:02 AM
by
TechCommunityAP
We have a syslog message with specific keywords for e.g.. "content found". if the syslog message doesn't flow in log analytics. we need to create an alert for the syslog.
Appreciate your help on this one.
Thanks
Mar 21 2022 03:25 AM
You will need to adjust the Column name if its not SyslogMessage and the string to search on
Syslog
| where TimeGenerated > ago(4h)
| where SyslogMessage has "Failed to"
or
Syslog
| where TimeGenerated > ago(4h)
| where SyslogMessage has_any ('Failed to','err')