Every now and then, one of my cameras will hiccup and I will get thousands of log entries in the span of a few minutes about buffer overflow. I have a script which watches syslog for this, and if it finds more than some preset thresholds in a given span of time, it throws a semaphore and checks it every 10 minutes. If after 30 minutes the warnings persist, it will restart ZM. My question is, can someone help me with the logcheck ignore statement/file for these buffer overlow log entries? They look like
Code: Select all
Dec 17 22:32:40 zm_server_name zmc_m4[7014]: WAR [Buffer overrun at index 23, image 123, slow down capture, speed up analysis or increase ring buffer size]
So I am looking to make logcheck ignore "WAR [Buffer overrun at index" entries. Logcheck sends me output from my log watcher script, so I know if these warnings are there, but I dont want logcheck files emailed to me that have thousands of lines of these warnings. Any suggestions?