How can I parse/ transform text log data before it gets captured in SCOM 2007 R2?

Posted by Abs on Server Fault See other posts from Server Fault or by Abs
Published on 2010-05-04T21:12:16Z Indexed on 2010/05/04 21:19 UTC
Read the original article Hit count: 385

I'm pretty much a noob with System Center Operations Manager 2007, and I'm probably missing something pretty basic, but I'm stumped anyway. We're setting up monitoring on some of our servers, and we'd like to capture data from some plain text log files (e.g. DNS debug logs, DHCP logs). It looks to me like I can set up a generic text file monitoring rule and get events captured into the main Ops Manager database, but my understanding is that the whole line of text from the plain text log gets captured as one field. In an ideal world, we'd be able to parse or transform that log file data to make it easier to query later. Is this possible? Is it easy? Do I have to buy expensive 3rd-party software to do it?

One more thing: it would be even better if there was a way to stuff this data into the Audit Collection Services (ACS) database instead of the main one, but I'll take what I can get. Any help would be greatly appreciated.

© Server Fault or respective owner

Related posts about scom

Related posts about scom-2007-r2