Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rule name: Excessive swap utilization
- Alert rule: %mempools.mempool_descr ~ "Swap@" && %mempools.mempool_perc >= "50"
- Alert query: SELECT * FROM mempools WHERE (mempools.device_id = ?) && (mempools.mempool_descr REGEXP "Swap.*" && mempools.mempool_perc >= "50" )
- Rule match: no match
- Rule name: Devices up/down
- Alert rule: %macros.device_down = "1"
- Alert query: SELECT * FROM devices WHERE (devices.device_id = ?) && (((devices.status = 0 && ((devices.disabled = 0 && devices.ignore = 0)))) = "1")
- Rule match: no match
- Rule name: Device rebooted
- Alert rule: %devices.uptime < "300" && %macros.device = "1"
- Alert query: SELECT * FROM devices WHERE (devices.device_id = ?) && (devices.uptime < "300" && ((devices.disabled = 0 && devices.ignore = 0)) = "1")
- Rule match: no match
- Rule name: Port utilisation over threshold
- Alert rule: %macros.port_usage_perc >= "80" && %macros.port_up = "1" && %macros.port = "1"
- Alert query: SELECT * FROM ports WHERE (ports.device_id = ?) && ((((ports.ifInOctets_rate*8) / ports.ifSpeed)*100) >= "80" && ((ports.ifOperStatus = "up" && ports.ifAdminStatus = "up" && ((ports.deleted = 0 && ports.ignore = 0 && ports.disabled = 0)))) = "1" && ((ports.deleted = 0 && ports.ignore = 0 && ports.disabled = 0)) = "1")
- Rule match: no match
- Rule name: Sensor over limit
- Alert rule: %sensors.sensor_current > %sensors.sensor_limit && %sensors.sensor_alert = "1" && %macros.device_up = "1"
- Alert query: SELECT * FROM sensors,devices WHERE (( devices.device_id = sensors.device_id ) && sensors.device_id = ?) && (sensors.sensor_current > sensors.sensor_limit && sensors.sensor_alert = "1" && ((devices.status = 1 && ((devices.disabled = 0 && devices.ignore = 0)))) = "1")
- Rule match: no match
- Rule name: Sensor under limit
- Alert rule: %sensors.sensor_current < %sensors.sensor_limit_low && %sensors.sensor_alert = "1" && %macros.device_up = "1"
- Alert query: SELECT * FROM sensors,devices WHERE (( devices.device_id = sensors.device_id ) && sensors.device_id = ?) && (sensors.sensor_current < sensors.sensor_limit_low && sensors.sensor_alert = "1" && ((devices.status = 1 && ((devices.disabled = 0 && devices.ignore = 0)))) = "1")
- Rule match: no match
- Rule name: Wireless Sensor over limit
- Alert rule: %wireless_sensors.sensor_current >= %wireless_sensors.sensor_limit && %wireless_sensors.sensor_alert = "1" && %macros.device_up = "1"
- Alert query: SELECT * FROM wireless_sensors,devices WHERE (( devices.device_id = wireless_sensors.device_id ) && wireless_sensors.device_id = ?) && (wireless_sensors.sensor_current >= wireless_sensors.sensor_limit && wireless_sensors.sensor_alert = "1" && ((devices.status = 1 && ((devices.disabled = 0 && devices.ignore = 0)))) = "1")
- Rule match: no match
- Rule name: Wireless Sensor under limit
- Alert rule: %wireless_sensors.sensor_current <= %wireless_sensors.sensor_limit_low && %wireless_sensors.sensor_alert = "1" && %macros.device_up = "1"
- Alert query: SELECT * FROM wireless_sensors,devices WHERE (( devices.device_id = wireless_sensors.device_id ) && wireless_sensors.device_id = ?) && (wireless_sensors.sensor_current <= wireless_sensors.sensor_limit_low && wireless_sensors.sensor_alert = "1" && ((devices.status = 1 && ((devices.disabled = 0 && devices.ignore = 0)))) = "1")
- Rule match: no match
- Rule name: High memory usage
- Alert rule: %mempools.mempool_descr ~ "Virtual@" && %mempools.mempool_perc >= "92" && %devices.os !~ "FreeBSD"
- Alert query: SELECT * FROM mempools,devices WHERE (( devices.device_id = mempools.device_id ) && mempools.device_id = ?) && (mempools.mempool_descr REGEXP "Virtual.*" && mempools.mempool_perc >= "92" && devices.os NOT REGEXP "FreeBSD" )
- Rule match: no match
- Rule name: Partition 90%+ full
- Alert rule: %storage.storage_perc >= "90" && %devices.os !~ "FreeBSD"
- Alert query: SELECT * FROM storage,devices WHERE (( devices.device_id = storage.device_id ) && storage.device_id = ?) && (storage.storage_perc >= "90" && devices.os NOT REGEXP "FreeBSD" )
- Rule match: no match
- Rule name: sshd down
- Alert rule: %services.service_type = "ssh" && %services.service_status = "2" && %macros.device_up = "1"
- Alert query: SELECT * FROM services,devices WHERE (( devices.device_id = services.device_id ) && services.device_id = ?) && (services.service_type = "ssh" && services.service_status = "2" && ((devices.status = 1 && ((devices.disabled = 0 && devices.ignore = 0)))) = "1" )
- Rule match: no match
- Rule name: Test
- Alert rule: %devices.hostname ~ "wts-jail"
- Alert query: SELECT * FROM devices WHERE (devices.device_id = ?) && (devices.hostname REGEXP "wts-jail" )
- Rule match: matches
- Found 4 contacts to send alerts to.
- administrator<ITUnixAdmin@mso.umt.edu>
- Jon Robinson<jon.robinson@mso.umt.edu>
- Ryan Synder<ryan.snyder@mso.umt.edu>
- Shayne Johnson<shayne.johnson@mso.umt.edu>
- Found 1 transports to send alerts to.
- Transport: mail
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement