I have created 2 alerts which monitor the syslog for a regular expression and alert if the expression is seen in the past 5 minutes. I am unable to get these alerts working. What am I doing wrong?
OpenVPN Disconnect:
syslog.timestamp >= “macros.past_5m” AND syslog.msg REGEXP “SIGTERM”
OpenVPN Connect:
syslog.timestamp >= “macros.past_5m” AND syslog.msg REGEXP “Peer Connection Initiated”