|
First thing to do is to identify examples of the messages you want to catch, and look for similarities. Maybe you can give a list of event IDs with an Event Source string, if they come from the same program. If this won't work, then try the regexp match (you can create all sorts of regexps to match almost anything including multiple pattersns and so on)
If you have a particularly difficult list of matches, then you can create multiple filters (remember, only the FIRST match is used).
I cant give you much help unless I have details on exactly what event you want to match. Usually, the best way to go is to match the Source and EventID if possible, and use regexp as a last resort
_________________ Steve Shipway UNIX Systems, ITSS, University of Auckland, NZ Woe unto them that rise up early in the morning... -- Isaiah 5:11
|