This topic describes how to configure a custom monitoring product of the Match and Search for Alerts type.
Background information
You can configure a monitoring product of the Match and Search for Alerts type to monitor a keyword at a fixed position and send alert notifications. You can use the complete or partial content of a log that contains the keyword as the alert notification content.
A monitoring product of the Match and Search for Alerts type can be used only to send alert notifications. This monitoring product type does not collect statistics or allow you to view statistics.
For more information about scenarios of metrics, see Overview.
To configure a custom monitoring product, perform the following steps:
Step 1: Select a monitoring product type
Log on to the Real-time Monitoring Service (RMS) console. In the left-side navigation pane, click Custom Monitoring.
On the Custom Monitoring page, click Add.
On the Advanced tab, click Match and Search for Alerts to go to the configuration page of the monitoring product.
Step 2: Configure basic information of the monitoring product
In the Basic Information section, set the following parameters as required:
Monitoring Configuration Name: Enter a custom name for the monitoring product.
Application: Select the application to which the monitoring product belongs.
Collect Log File: Select a log file. You can use one of the following methods to select a log file:
Scan to Select: If no log file is displayed in the drop-down list, perform the following steps. By default, Scan to Select is selected.
Click Scan to Select. The Select Collection File dialog box appears.
Double-click a path and select a log file.
If you do not find the required log file in the default file path, set the Specify Root Directory or Specify Server IP Address parameter to find the required log file. When you find the required log file, you need to set only the Specify Root Directory or Specify Server IP Address parameter.
Click the name of the required log file, and then click OK.
Enter the log path: Enter a log file path. Pay attention to the path rule.
Enable: Specify whether to turn on the Enable switch. By default, the Enable switch is turned on.
Description: Optional. Enter a description for the monitoring product.
Optional. Click Advanced Options and set the parameters as required.
Log Encoding: RMS automatically identifies the encoding format for logs. GBK and UTF-8 are supported. If the encoding format is not identified, you can enter the encoding format in the Log Encoding field.
Cluster Log Throttling: Specify the upper limit of the speed for collecting logs. Unit: KB/min. After the size of logs collected per minute reaches the upper limit, the remaining logs are no longer collected. This results in data inaccuracy.
Remark for Soft Link in Log Path: Enter the symbolic link in the log file path. Example:
/home/admin/logs. If the log file path that you entered contains a symbolic link, enter the symbolic link in this field.Maximum Storage Capacity: Select a storage capacity.
Upper Limit of Report Keys: Enter the upper limit of report keys. The keys that exceed the upper limit are discarded.
Step 3: Configure filter conditions for log
The default environment for metadata collection is Online. You can also select the phased environment and staging environment. Statistics can be collected from one or more logic data centers (LDC), Internet data centers (IDC), or single machines.
If you need to specify multiple LDCs, IDCs, or single machines, separate the specified items with commas (,). Regular expressions are not supported.
Step 4: Configure log matching rule
In the log matching configuration section, you can set the following parameters to enable log matching by keywords: Log Matching, New Whitelist Matching Rule, and Add Blacklist Matching Rule.
The whitelist is equivalent to the
[Where Field =?]SQL clause. The blacklist is equivalent to the[Where Field < >?]SQL clause.The columns specified in the whitelist are in the AND relationship.
The columns specified in the whitelist and those in the blacklist are in the AND relationship.
The columns specified in the blacklist are in the OR relationship.
The following procedure uses the New Whitelist Matching Rule parameter as an example.
Click New Whitelist Matching Rule.
Click Select a column value. In the Column Definition dialog box that appears, specify a position to add a column to the whitelist.
Use the pointer to select a keyword in the Log Sample section. Then, RMS automatically generates a rule for selecting a column value based on the position of the keyword. At the same time, the sample column value that is selected based on the rule appears in the Column Value Sampling table.
Enter the column name in the lower-right corner and click OK.
Set the Whitelist Value parameter.
You can specify one or more values for a column in the whitelist. Separate multiple values with commas (,). Example:
aaaa,bbbb,cccc.
Step 5: Specify the alert notification content
You can select Use Default Text or Use Custom Text and specify custom alert notification content.
You can use the complete content of a log as the alert notification content. Alternatively, you can use a regular expression to extract partial content of a log as the alert notification content.
Step 6: Configure alert rule
By default, a monitoring product of the Match and Search for Alerts type uses the complete content of a log as the alert notification content. In the Alert Configuration section, set the following parameters to configure an alert rule:
Alert Title: the title for an alert notification.
Maximum log count in alarms: the maximum number of logs that can be sent at a time.
Minimum count of matched logs for triggering an IM alert: the condition that triggers an alert notification sent by an instant message (IM).
Minimum number of matched logs for triggering an SMS alarm: the condition that triggers an alert notification sent by a text message.
Alert Level: the alert severity. Valid values: Common Alert (P2), Orange Alert (P1), and Red Alert (P0).
Emergency text: the content to be sent to the emergency contact.
Emergency link: the emergency response link. The emergency response link and content will be sent together.
Step 7: Diagnose the configuration
After you perform the preceding steps, the monitoring product is configured. Click the monitoring product that you configured to go to the details page of the monitoring product. Click Configure Diagnostic Assistant in the upper-right corner to diagnose your configurations in the preceding steps. You can obtain the following diagnostic feedback about detected issues:
Causes
Diagnosis results
Suggestions