locked
SCOM 2016 - Event based Collection rule for Generic CSV text log doesn't work RRS feed

  • Question

  • Hi,

    Please can someone assist.

    I have created a simple rule to detect the word 'Pass' in a comma delimited CSV file. I set the target to Windows Server Operating System, disabled it and added an override for my test server.

    The CSV contents are below: app01,test,Pass

    On the Expression I have set 'Params/Param[3] Equals Pass'. The position of 'Pass' is in the 3rd field so it looks ok to me.

    I then created an Event view for this rule, and it shows nothing. I have attached pictures of all the steps below:


    Saturday, August 15, 2020 10:31 AM

All replies

  • Hi Jay,

    To create a rule for CSV text log, we suggest to create a Generic CSV text log (Alert) rule instead.

    Here is a link with detail steps for the reference:
    https://www.youtube.com/watch?v=2lBOVepCOkQ
    Note: Non-Microsoft link, just for the reference.

    Hope it can help.

    Tips: This SCOM Forum will be migrating to a new home on Microsoft Q&A, please refer to this sticky post for more details.

    Best regards.
    Crystal   


    "SCOM" forum will be migrating to a new home on   Microsoft Q&A!
      We invite you to post new questions in the "SCOM" forum's new home on   Microsoft Q&A!
      For more information, please refer to the sticky post.

    Monday, August 17, 2020 7:57 AM
  • Hi Jay,

    How's everything going? Did we try the "Generic CSV Text log (Alert)" rule? Was it working? If there's any update, feel free to let us know.

    Best regards.

    Crystal


    "SCOM" forum will be migrating to a new home on   Microsoft Q&A!
      We invite you to post new questions in the "SCOM" forum's new home on   Microsoft Q&A!
      For more information, please refer to the sticky post.

    Thursday, August 20, 2020 6:08 AM