Parsing timestamps
Talking about the timestamps on the lines we pushed into Zabbix, the date and time in the file didn't match the date and time displayed in Zabbix. Zabbix marked the entries with the time it collected them. This is fine in most cases when we're doing constant monitoring; content is checked every second or so, gathered, timestamped, and pushed to the server. When parsing some older data, the timestamps can be way off, though. Zabbix does offer a way to parse timestamps out of the log entries.
Let's use our very first log file monitoring item for this.
Navigate to Configuration | Hosts, click on Items next to A test host, and click on First logfile in the Name column. Notice the Log time format field; that's what we'll use ...
Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Read now
Unlock full access