<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
	<title><![CDATA[Forums]]></title>
	<link><![CDATA[http://www.systemcentercentral.com/Forums/tabid/60/rss/1/tag/Forums%20Operations_Manager/Default.aspx]]></link>
	<description></description>
	<language>en-us</language>
	<copyright><![CDATA[Copyright 2009 System Center Central All Rights Reserved.]]></copyright>
	<lastBuildDate>Sat, 04 Sep 2010 00:39:25 GMT</lastBuildDate>
		<item>
			<title><![CDATA[Forums: Alert-Generating Rule for Syslog Messages]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79960/Default.aspx]]></link>
			<description><![CDATA[<p>Hi,</p>
<p>I'm trying to set up an alert-generating rule to generate alerts for specific syslog messsages, and am running into a bit of a wall. Perhaps someone else has gotten this working? </p>
<p>As a bit of background, I've configured one of my monitored Cisco devices (an ASA) to forward syslog messages to my RMS. I also have the xSNMP Syslog Alerts working, so I know that the RMS is, in fact, receiving syslog messages. (A <span style="font-family: Courier New;">nestat -an | findstr 514</span> also shows that the RMS is listening on UDP 514)</p>
<p>However, while the xSNMP Syslog Alerts look for syslog events by severity, I would like to search for specific messages, by looking for certain event #'s within the "message" parameter.</p>
<p>While I want to look for specific events, such as 733104 & 733105 (Possible Syn Flood attack), for this example/as a proof-of-concept I am looking for 106001, as those are presently being logged. In other words, when it's working, I'll know that it's working within a few minutes.</p>
<p>The goal is to be able to set up an Alert-Generating Syslog rule raising an alert for syslog messages where "facility" = 16, and "message" contains "106001". </p>
<p>A sample alert (from xSNMP alerts) looks like:</p>
<p><span style="font-family: Courier New;">Facility: 16<br />
Severity: 2<br />
Priority: local0.critical<br />
Timestamp: Sep 3  20:28:16</span></p>
<p><span style="font-family: Courier New;">Message: Sep 03 2010 14:29:22 FW1 : %ASA-2-106001: Inbound TCP connection denied from 69.69.31.28/1199 to xxx.xxx.xxx.xxx/135 flags SYN on interface Internet</span></p>
<p>I've followed the instructions at both, with no luck:</p>
<p>http://contoso.se/blog/?p=158</p>
<p>and</p>
<p>http://support.microsoft.com/kb/942863/en-us</p>
<p>...which slightly differ (the first one has the rule targeted at the MS, the second has it targeted at an agent, if memory serves). I've also tried rules targeted at "xSNMP  Device" and "SNMP Network Device" to no avail.</p>
<p>Here's the rest of the steps I have taken in my rule attempts:</p>
<ol>
    <li>Configure my Cisco ASA to forward syslog messages to my RMS.</li>
    <li>Authoring > Rules > New Rule</li>
    <li>Rule Type = Alert Generating > Syslog (Alert)</li>
    <li>Entered rule name & description</li>
    <li>Rule category = Alert</li>
    <li>Rule target (I've tried Root management server, agent, SNMP network device, xsnmp network device; should I be trying something else?)</li>
    <li>Expression: "facility equals 16" (I decided to keep it simple and try to get everything, and then attempt to filter it down by a string with the messsage parameter; better more results than none, to begin with)</li>
    <li>Set up the alert name, description, set severity to "Information" (for now, so any output doesn't get lost in the xSNMP alerts, which are all Critical & Warning).</li>
</ol>
<p>The properties/configuration of the completed rule(s) shows the Data Source as "SyslogDS" and the Response as "Alert".</p>
<p>So far, no luck.</p>
<p>So, I guess the question is, how does one create an alert-generating syslog rule (that actually generates alerts)? I think the problem lies either within the targeting of the rule, or maybe the rule category?</p>
<p>Any insight appreciated!</p>
<p>Thanks!</p>
<p> </p>
<p> </p>]]></description>
			<pubDate>Fri, 03 Sep 2010 20:56:17 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79960/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: Re: CU2 installation: Agents never show up in Pending]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/indexId/79942/tag/Forums+Operations_Manager/Default.aspx]]></link>
			<description><![CDATA[Are your management servers windows 2008, or 2003?<br><br>I've seen incomplete patch installs in 2008 when the patch was not started with 'run as administrator' option.]]></description>
			<pubDate>Fri, 03 Sep 2010 16:01:21 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/indexId/79942/tag/Forums+Operations_Manager/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: RE: Re: CU2 installation: Agents never show up in Pending]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79959/Default.aspx]]></link>
			<description><![CDATA[<p>Found it.</p>
<p>I found a blog somewhere (wish I had the link to give them credit) that said that sometimes even though you use an elevated cmd prompt it doesn't always work.  It said to disable UAC, reboot, and try again.</p>
<p>As soon as I did that, everything worked perfectly.  No idea why, but it did.</p>]]></description>
			<pubDate>Fri, 03 Sep 2010 19:55:02 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79959/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: R2: Trying to upgrade from SQL 2005 to 2008]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79849/Default.aspx]]></link>
			<description><![CDATA[<p><a href="http://technet.microsoft.com/en-us/library/dd789004.aspx">http://technet.microsoft.com/en-us/library/dd789004.aspx</a></p>
<p>We're trying to run step #5, but it is failing.  In the MSI install log we see:</p>
<p>...</p>
<p>(date) (time) Error: AddWebConfigAppSettingCA: Error: could not get MG ID from MG Server name</p>
<p>...</p>
<p>We see that error after the install stalls for almost exactly 20 minutes.</p>
<p>Any ideas?  We're trying to upgrade an install that is currently functional.</p>
<p>All the permissions seem to be fine.</p>]]></description>
			<pubDate>Thu, 02 Sep 2010 19:11:23 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79849/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: ACS in a DMZ scenario?]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/78926/Default.aspx]]></link>
			<description><![CDATA[<p>I have what I would consider a fairly typical setup with a DMZ which is separated from the corporate network by a firewall. The servers in the DMZ are on a separate domain and are reporting back to SCOM via gateway servers, other than that they have no communication to the internal network.</p>
<div style="margin: 0in 0in 10pt">I’m in the early stages of starting to deploy ACS in our environment. What I’m wondering about is how to go about deploying ACS in this DMZ. I know that there is a 1 to 1 relationship with the collector and the database so I’m assuming that if that is how it has to be then I would have to have a separate database server for ACS in the DMZ. Can the ACS Collection service be run from a gateway server? If not any guidance on how to setup ACS for a DMZ environment.</div>]]></description>
			<pubDate>Fri, 27 Aug 2010 19:26:12 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/78926/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: Re: ACS in a DMZ scenario?]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/indexId/79945/tag/Forums+Operations_Manager/Default.aspx]]></link>
			<description><![CDATA[I’m in the financial industry, and the auditors are requiring that we centrally collect all security event logs.  ACS was to be our solution for this to keep the overhead of security events for 400+ servers out of the operations database.  I think I can live with a separate ACS database if that is doable, though I’m not sure how reporting on that database would work.]]></description>
			<pubDate>Fri, 03 Sep 2010 16:51:07 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/indexId/79945/tag/Forums+Operations_Manager/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: RE: In house developed monitor failures (EventID 1206 failed, got unloaded and reached the failure limit that prevents automatic reload. Management group "".)]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79943/Default.aspx]]></link>
			<description><![CDATA[<p>I'm working with Cliff to resolved this issue. </p>
<p>As suggest, I try to run the script manually using the command line. The script complete sucessfully and return the expected XML.</p>
<p>The Mp containing the vbs is available here : http://pastebin.com/JL9KtQJm</p>
<p> </p>
<p>Using the function LogScriptEvent(), I manage to figure out the call to oAPI.Return() hang when the propertybag is too big.</p>]]></description>
			<pubDate>Fri, 03 Sep 2010 16:07:38 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79943/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: CU2 installation: Agents never show up in Pending]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79894/Default.aspx]]></link>
			<description><![CDATA[<p>I'm in the middle of upgrading to CU2 and am having an issue getting the agents to show up as pending upgrade.</p>
<p>At first, I had done the installation with my account, which has all the access needed (even SA).  Everything went fine, but I noticed the update packages didn't get put into the agentmanagement folders.  I manually copied them in, but this didn't change anything (even after cycling the HS on the RMS and each MS).</p>
<p>Then I logged in as the action account, which is also local admin and SA.  Install went fine again, it DID copy the files into place, but still the agents don't show up in pending.</p>
<p>I manually updated two agents, and they show up just fine as having the CU2 update in the agent view.  But I can't get any of the other agents to show up in pending.  Am I going to have to resort to a 3rd party tool to push the update out?</p>]]></description>
			<pubDate>Fri, 03 Sep 2010 04:42:34 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79894/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: Servers with Multiple NIC's and agent health]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79875/Default.aspx]]></link>
			<description><![CDATA[<p>I have a number of servers with two NIC’s. One NIC has a private IP address 10.x.x.x and the other has a public facing NIC. These servers sit behind a SCOM gateway server with two NICs. My problem is that in OpMan console these servers (including the Gateway) sometimes go gray from green and then back again. A ticket with MS determined the certs were OK. So I made sure that each NIC with a private IP address was in 1<sup>st</sup> place in the binding order. No go. I then edited the hosts file so that the FQDN was hardcoded to an internal address. Still no go.</p>
<div style="margin: 0in 0in 10pt">The health service and eventvwr on all of these servers show everything as OK. Thoughts?</div>]]></description>
			<pubDate>Thu, 02 Sep 2010 23:46:18 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79875/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: Re: CU2 installation: Agents never show up in Pending]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/indexId/79934/tag/Forums+Operations_Manager/Default.aspx]]></link>
			<description><![CDATA[I should have mentioned that I followed his blog while doing my installation.  I even saw his section about the agent patch files not being put in place which is what clued me into looking there.  I've also posted this exact question to his blog in hopes that he might also see it and respond.<br><br><br><br>I get no errors at all.  None on the RMS, MS's, GW's, or agents.  They all just go along as if nothing is wrong.<br><br><br><br>I've contacted the team that manages our package deployment utility (similar to SCCM) to see what it'll take to make a package.  I'm at a complete loss as to why this might be happening.]]></description>
			<pubDate>Fri, 03 Sep 2010 14:56:53 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/indexId/79934/tag/Forums+Operations_Manager/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: RE: Re: Generic Log .txt Monitor HELP!]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79932/Default.aspx]]></link>
			<description><![CDATA[<p>No, I mean it only seems to find the text string once and create an alert. All appearances of the text string after the initial alert seem to be ignored. As if it stops looking for it all together. Even inserting the text manually into the log file doesnt seem to affect the alert.</p>]]></description>
			<pubDate>Fri, 03 Sep 2010 14:38:16 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79932/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: Alerting when Task Scheduelr service is not running]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/78741/Default.aspx]]></link>
			<description><![CDATA[<p>Hello everyone!</p>
<p>This is my first post here and I'm seeking your collective SCOM know-how. I am a newbie with the software so Im sure what I am asking is easy to configure and probably somewhere within these forums so I apologize in advance.</p>
<p>I have been tasked with creating a notification via email (already figured out subscriptions and notification channels etc and am being alerted for other things) when a particular service is NOT running on our windows servers. I may apply this to other services in the future, but for right now, the service I am trying to monitor its runnign state is the Task Scheduler service. </p>
<p>Can anyone PLEASE guide me as to how to achieve this goal?  Any help and advice is most definitely appreciated!</p>
<p>Thanks</p>
<p>David</p>]]></description>
			<pubDate>Thu, 26 Aug 2010 16:44:48 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/78741/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: Re: Alerting when Task Scheduelr service is not running]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/indexId/79931/tag/Forums+Operations_Manager/Default.aspx]]></link>
			<description><![CDATA[You should get an Alert when it's down, then you right-click the Alert and create a new Notification subscription.<br><br>But since you didn't get the Alert yet, this won't work. You have to go to the Administration Tab, right-click Subscriptions, "New subscription...", insert a name, then tick "created by specific rules or monitors" and in the Criteria description box you see "specific", click it, search for the Monitor, add it. Next, next...]]></description>
			<pubDate>Fri, 03 Sep 2010 14:28:18 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/indexId/79931/tag/Forums+Operations_Manager/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: Re: Alerting when Task Scheduelr service is not running]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/indexId/79930/tag/Forums+Operations_Manager/Default.aspx]]></link>
			<description><![CDATA[Anyone?  Please?  Thanks! :)]]></description>
			<pubDate>Fri, 03 Sep 2010 14:04:15 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/indexId/79930/tag/Forums+Operations_Manager/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: RE: CU2 installation: Agents never show up in Pending]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79911/Default.aspx]]></link>
			<description><![CDATA[<p>Bob, what sort of error messages are you seeing on the RMS or clients that are not updated? Any warning messages of any sort? Not sure if you've seen Kevin's CU2 rundown, which may have a nugget that helps.</p>
<h3><a onmousedown="return si_T('&ID=SERP,5031.1')" href="http://blogs.technet.com/b/kevinholman/archive/2010/04/30/opsmgr-2007-r2-cu2-rollup-hotfix-ships-and-my-experience-installing-it.aspx" realurl="http://blogs.technet.com/b/kevinholman/archive/2010/04/30/opsmgr-2007-r2-cu2-rollup-hotfix-ships-and-my-experience-installing-it.aspx"><font color="#0044cc">OpsMgr 2007 R2 <strong>CU2</strong> rollup hotfix ships – and my experience ...</font></a></h3>]]></description>
			<pubDate>Fri, 03 Sep 2010 08:59:07 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79911/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: RE: Servers with Multiple NIC's and agent health]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79910/Default.aspx]]></link>
			<description><![CDATA[<p>You'll find the cause in the error events. Find the error events in the 20,000 - 21,000 range in the OpsMgr Event Log on the agent computer, then on the mgmt server. Check them against the authentication event reference on the WIKI that I posted - <a href="http://www.systemcentercentral.com/BlogDetails/tabid/143/IndexID/32926/Default.aspx"><font color="#003f7d">http://www.systemcentercentral.com/BlogDetails/tabid/143/IndexID/32926/Default.aspx</font></a></p>]]></description>
			<pubDate>Fri, 03 Sep 2010 08:54:33 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79910/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: scom snmp monitoring]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79805/Default.aspx]]></link>
			<description><![CDATA[<p>Hello Guru's, </p>
<p>I have a request to monitor a few devices - datapower x150, apache httpd and IBM webshpere. </p>
<p>The application owners have sent us the MIB's. And we want to configure these into scom for alerting. </p>
<p>Any idea how we can get this done?</p>
<p>Thanks</p>]]></description>
			<pubDate>Thu, 02 Sep 2010 14:20:08 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79805/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: Any good .net MPs out there?]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79682/Default.aspx]]></link>
			<description><![CDATA[<p>I ran across this one. Do you have any other suggestions or feedback?</p>
<p><a href="http://www.avicode.com/AVIcodeOpsMgr2007/3/opsmgr2007features.htm">http://www.avicode.com/AVIcodeOpsMgr2007/3/opsmgr2007features.htm</a></p>]]></description>
			<pubDate>Wed, 01 Sep 2010 21:28:15 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79682/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: Event Based Rule needed with Repeated Event abilities]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79869/Default.aspx]]></link>
			<description><![CDATA[<p>Hi,</p>
<p>I've set up rules that monitor the application log for specific Events and this works fine. When an event is dropped in the Event Log, an Error is generated in SCOM. These events sometimes happen frequently and I've specified a Repeat Count to prevent the Alert Console from being flooded.</p>
<p>Now I have a customer request to only alert if the problem happens twice within a 5 minute time frame and I can't figure out how to do this (Monitors have a repeat setting with a counting mode, but lack the Repeat Count that prevents flooding).</p>
<p>How can I edit the rule or management pack to only alert if the problem occurs twice?</p>
<p>Thx</p>]]></description>
			<pubDate>Thu, 02 Sep 2010 22:56:08 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79869/Default.aspx</guid>
		</item>
		<item>
			<title><![CDATA[Forums: RE: Event Based Rule needed with Repeated Event abilities]]></title>
			<link><![CDATA[http://www.systemcentercentral.com/tabid/177/IndexId/79897/Default.aspx]]></link>
			<description><![CDATA[<p>I believe what you're looking for can be accomplished with a "Repeated Event Detection Monitor" instead of a rule.  Go to Authoring, add a new Monitor, look under Windows Events, and choose "Repeated Event Detection".  In there you can do Manual resets (operator has to close the alert manually), Timed resets (after a certain period the alert clears itself), or Windows Event Reset (alert clears when a separate event is detected in the event logs).</p>]]></description>
			<pubDate>Fri, 03 Sep 2010 05:09:28 GMT</pubDate>
			<guid>http://www.systemcentercentral.com/tabid/177/IndexId/79897/Default.aspx</guid>
		</item>
	</channel>
</rss>
