Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rule name: CAUTION Device has been rebooted
- Alert rule: %devices.uptime < "300" && %macros.device = "1"
- Alert query: SELECT * FROM devices WHERE (devices.device_id = ?) && (devices.uptime < "300" && ((devices.disabled = 0 && devices.ignore = 0)) = "1" )
- Rule match: no match
- Rule name: WARNING Network Port utilization over 75%
- Alert rule: %macros.port_up = "1" && %macros.port = "1" && %macros.port_usage_perc >= "75"
- Alert query: SELECT * FROM ports WHERE (ports.device_id = ?) && (((ports.ifOperStatus = "up" && ports.ifAdminStatus = "up" && ((ports.deleted = 0 && ports.ignore = 0 && ports.disabled = 0)))) = "1" && ((ports.deleted = 0 && ports.ignore = 0 && ports.disabled = 0)) = "1" && (((ports.ifInOctets_rate*8) / ports.ifSpeed)*100) >= "75" )
- Rule match: no match
- Rule name: CAUTION Sensor over limit - Check Device
- Alert rule: %sensors.sensor_current > %sensors.sensor_limit && %sensors.sensor_alert = "1" && %macros.device_up = "1"
- Alert query: SELECT * FROM sensors,devices WHERE (( devices.device_id = sensors.device_id ) && sensors.device_id = ?) && (sensors.sensor_current > sensors.sensor_limit && sensors.sensor_alert = "1" && ((devices.status = 1 && ((devices.disabled = 0 && devices.ignore = 0)))) = "1" )
- Rule match: no match
- Rule name: CAUTION Sensor under limit - Check Device
- Alert rule: %sensors.sensor_current < %sensors.sensor_limit_low && %sensors.sensor_alert = "1" && %macros.device_up = "1"
- Alert query: SELECT * FROM sensors,devices WHERE (( devices.device_id = sensors.device_id ) && sensors.device_id = ?) && (sensors.sensor_current < sensors.sensor_limit_low && sensors.sensor_alert = "1" && ((devices.status = 1 && ((devices.disabled = 0 && devices.ignore = 0)))) = "1" )
- Rule match: no match
- Rule name: Service not responding Ping/HTTP/DNS/NTP
- Alert rule: %services.service_status != "0"
- Alert query: SELECT * FROM services WHERE (services.device_id = ?) && (services.service_status != "0" )
- Rule match: no match
- Rule name: CRITICAL Processors usage over 80% last 5m
- Alert rule: %macros.past_5m = %processors.processor_usage >= "80"
- Alert query: SELECT * FROM processors WHERE (processors.device_id = ?) && ((DATE_SUB(NOW(),INTERVAL 5 MINUTE)) = processors.processor_usage >= "80" )
- Rule match: no match
- Rule name: Poller is taking too long
- Alert rule: %pollers.time_taken >= "250"
- Alert query:
- Rule match: no match
- Rule name: WARNING Storage at Warning Level
- Alert rule: %storage.storage_descr !~ "/boot" && %storage.storage_perc > %storage.storage_perc_warn
- Alert query: SELECT * FROM storage WHERE (storage.device_id = ?) && (storage.storage_descr NOT REGEXP "/boot" && storage.storage_perc > storage.storage_perc_warn )
- Rule match: no match
- Rule name: CAUTION Syslog, authentication failure on Device
- Alert rule: %syslog.timestamp > = %macros.past_5m && %syslog.msg ~ "@authentication failure@"
- Alert query: SELECT * FROM syslog WHERE (syslog.device_id = ?) && (syslog.timestamp > = (DATE_SUB(NOW(),INTERVAL 5 MINUTE)) && syslog.msg REGEXP ".*authentication failure.*" )
- Rule match: no match
- Rule name: WARNING Device Memory High Usage
- Alert rule: %mempools.mempool_descr = "Virtual memory" && %mempools.mempool_perc >= "70"
- Alert query: SELECT * FROM mempools WHERE (mempools.device_id = ?) && (mempools.mempool_descr = "Virtual memory" && mempools.mempool_perc >= "70" )
- Rule match: no match
- Rule name: CAUTION Login failure on network device
- Alert rule: %syslog.timestamp >= %macros.past_5m && %syslog.msg ~ "@Invalid user name/password@"
- Alert query: SELECT * FROM syslog WHERE (syslog.device_id = ?) && (syslog.timestamp >= (DATE_SUB(NOW(),INTERVAL 5 MINUTE)) && syslog.msg REGEXP ".*Invalid user name/password.*" )
- Rule match: no match
- Rule name: WARNING Device has High Packet Loss
- Alert rule: %macros.packet_loss_5m >= "10"
- Alert query: SELECT * FROM device_perf WHERE (device_perf.device_id = ?) && ((((DATE_SUB(NOW(),INTERVAL 5 MINUTE)) && device_perf.loss)) >= "10" )
- Rule match: no match
- Rule name: WARNING Device High Network Latency
- Alert rule: %macros.icmp_response >= "90"
- Alert query: SELECT * FROM device_perf WHERE (device_perf.device_id = ?) && ((((DATE_SUB(NOW(),INTERVAL 5 MINUTE)) && device_perf.avg)) >= "90" )
- Rule match: no match
- Rule name: WARNING Device Memory High Usage 2
- Alert rule: %mempools.mempool_descr ~ "Global Memory 1" || %mempools.mempool_descr ~ "Local Memory 1" && %mempools. >= "80"
- Alert query: SELECT * FROM mempools WHERE (mempools.device_id = ?) && (mempools.mempool_descr REGEXP "Global Memory 1" || mempools.mempool_descr REGEXP "Local Memory 1" && mempools. >= "80" )
- Rule match: no match
- Rule name: CAUTION Syslog Received Alert Message
- Alert rule: %syslog.timestamp >= %macros.past_5m && %syslog.priority ~ "alert"
- Alert query: SELECT * FROM syslog WHERE (syslog.device_id = ?) && (syslog.timestamp >= (DATE_SUB(NOW(),INTERVAL 5 MINUTE)) && syslog.priority REGEXP "alert" )
- Rule match: no match
- Rule name: CRITICAL Device Down Alert
- Alert rule: %macros.device_down = "1" && %devices.status_reason = "icmp"
- Alert query: SELECT * FROM devices WHERE (devices.device_id = ?) && (((devices.status = 0 && ((devices.disabled = 0 && devices.ignore = 0)))) = "1" && devices.status_reason = "icmp" )
- Rule match: no match
- Rule name: CAUTION Syslog Received Emergency Priority Msg
- Alert rule: %syslog.timestamp >= %macros.past_5m && %syslog.priority ~ "emerg" || %syslog.priority ~ "emergency"
- Alert query: SELECT * FROM syslog WHERE (syslog.device_id = ?) && (syslog.timestamp >= (DATE_SUB(NOW(),INTERVAL 5 MINUTE)) && syslog.priority REGEXP "emerg" || syslog.priority REGEXP "emergency" )
- Rule match: no match
- Rule name: Device discovered within the last 60 minutes
- Alert rule: %eventlog.type = "discovery" && %eventlog.message ~ "@autodiscovered@" && %eventlog.datetime >= %macros.past_60m
- Alert query: SELECT * FROM eventlog WHERE (eventlog.device_id = ?) && (eventlog.type = "discovery" && eventlog.message REGEXP ".*autodiscovered.*" && eventlog.datetime >= (DATE_SUB(NOW(),INTERVAL 60 MINUTE)) )
- Rule match: no match
- Rule name: A Duplicate IP address detected
- Alert rule: %syslog.timestamp >= %macros.past_5m && %syslog.msg ~ "@Duplicate@ "
- Alert query: SELECT * FROM syslog WHERE (syslog.device_id = ?) && (syslog.timestamp >= (DATE_SUB(NOW(),INTERVAL 5 MINUTE)) && syslog.msg REGEXP ".*Duplicate.* " )
- Rule match: no match
- Rule name: A duplicate MAC address is detected
- Alert rule: %syslog.timestamp >= %macros.past_5m && %syslog.msg ~ "@is flapping between port@"
- Alert query: SELECT * FROM syslog WHERE (syslog.device_id = ?) && (syslog.timestamp >= (DATE_SUB(NOW(),INTERVAL 5 MINUTE)) && syslog.msg REGEXP ".*is flapping between port.*" )
- Rule match: no match
- Rule name: Port with Duplex mismatch
- Alert rule: %syslog.timestamp >= %%macros.past_5m && %syslog.msg ~ "@duplex mismatch@"
- Alert query: SELECT * FROM syslog WHERE (syslog.device_id = ?) && (syslog.timestamp >= (DATE_SUB(NOW(),INTERVAL 5 MINUTE)) && syslog.msg REGEXP ".*duplex mismatch.*" )
- Rule match: no match
- Rule name: Interface has Possible Duplex Mismatch/or Line Issues
- Alert rule: %syslog.msg ~ "@Excessive CRC@" && %syslog.timestamp >= %macros.past_5m
- Alert query: SELECT * FROM syslog WHERE (syslog.device_id = ?) && (syslog.msg REGEXP ".*Excessive CRC.*" && syslog.timestamp >= (DATE_SUB(NOW(),INTERVAL 5 MINUTE)) )
- Rule match: no match
- Rule name: WARNING UPS Battery Needs Replacement
- Alert rule: %sensors.sensor_type ~ "upsAdvBatteryReplaceIndicator" && %sensors.sensor_current = "2"
- Alert query: SELECT * FROM sensors WHERE (sensors.device_id = ?) && (sensors.sensor_type REGEXP "upsAdvBatteryReplaceIndicator" && sensors.sensor_current = "2" )
- Rule match: no match
- Rule name: WARNING UPS Switched to Battery
- Alert rule: %sensors.sensor_current = "3" && %sensors.sensor_type = "upsBasicOutputStatus"
- Alert query: SELECT * FROM sensors WHERE (sensors.device_id = ?) && (sensors.sensor_current = "3" && sensors.sensor_type = "upsBasicOutputStatus" )
- Rule match: no match
- Rule name: WARNING UPS Hardware Failure Bypass
- Alert rule: %sensors.sensor_current = "10" && %sensors.sensor_type = "upsBasicOutputStatus"
- Alert query: SELECT * FROM sensors WHERE (sensors.device_id = ?) && (sensors.sensor_current = "10" && sensors.sensor_type = "upsBasicOutputStatus" )
- Rule match: no match
- Rule name: WARNING UPS Emergency Static Bypass
- Alert rule: %sensors.sensor_current = "16" && %sensors.sensor_type = "upsBasicOutputStatus"
- Alert query: SELECT * FROM sensors WHERE (sensors.device_id = ?) && (sensors.sensor_current = "16" && sensors.sensor_type = "upsBasicOutputStatus" )
- Rule match: no match
- Rule name: WARNING Bad PSU #1
- Alert rule: %sensors.sensor_oid = ".1.3.6.1.4.1.11.2.14.11.1.2.6.1.4.2" && %sensors.sensor_current = "2"
- Alert query: SELECT * FROM sensors WHERE (sensors.device_id = ?) && (sensors.sensor_oid = ".1.3.6.1.4.1.11.2.14.11.1.2.6.1.4.2" && sensors.sensor_current = "2" )
- Rule match: no match
- Rule name: CRITICAL Faulty Fan detected
- Alert rule: %sensors.sensor_oid = ".1.3.6.1.4.1.11.2.14.11.1.2.6.1.4.1" && %sensors.sensor_current = "2"
- Alert query: SELECT * FROM sensors WHERE (sensors.device_id = ?) && (sensors.sensor_oid = ".1.3.6.1.4.1.11.2.14.11.1.2.6.1.4.1" && sensors.sensor_current = "2" )
- Rule match: no match
- Rule name: CRITICAL Bad PSU #3
- Alert rule: %sensors.sensor_oid = " .1.3.6.1.4.1.11.2.14.11.1.2.6.1.4.4" && %sensors.sensor_current = "2"
- Alert query: SELECT * FROM sensors WHERE (sensors.device_id = ?) && (sensors.sensor_oid = " .1.3.6.1.4.1.11.2.14.11.1.2.6.1.4.4" && sensors.sensor_current = "2" )
- Rule match: no match
- Rule name: CRITICAL Bad PSU #4
- Alert rule: %sensors.sensor_oid = ".1.3.6.1.4.1.11.2.14.11.1.2.6.1.4.5" && %sensors.sensor_current = "2"
- Alert query: SELECT * FROM sensors WHERE (sensors.device_id = ?) && (sensors.sensor_oid = ".1.3.6.1.4.1.11.2.14.11.1.2.6.1.4.5" && sensors.sensor_current = "2" )
- Rule match: no match
- Rule name: CRITICAL Bad PSU #2
- Alert rule: %sensors.sensor_oid = ".1.3.6.1.4.1.11.2.14.11.1.2.6.1.4.3" && %sensors.sensor_current = "2"
- Alert query: SELECT * FROM sensors WHERE (sensors.device_id = ?) && (sensors.sensor_oid = ".1.3.6.1.4.1.11.2.14.11.1.2.6.1.4.3" && sensors.sensor_current = "2" )
- Rule match: no match
- Rule name: CAUTION UPS on Smart Trim
- Alert rule: %sensors.sensor_current = "12" && %sensors.sensor_type = "upsBasicOutputStatus"
- Alert query: SELECT * FROM sensors WHERE (sensors.device_id = ?) && (sensors.sensor_current = "12" && sensors.sensor_type = "upsBasicOutputStatus" )
- Rule match: no match
- Rule name: WARNING PoE Over Power on Switch
- Alert rule: %syslog.msg ~ "@PoE usage has exceeded threshold of 80@" && %syslog.timestamp = %macros.past_5m
- Alert query: SELECT * FROM syslog WHERE (syslog.device_id = ?) && (syslog.msg REGEXP ".*PoE usage has exceeded threshold of 80.*" && syslog.timestamp = (DATE_SUB(NOW(),INTERVAL 5 MINUTE)) )
- Rule match: no match
- Rule name: CAUTION Check Switch for ARP Protect config
- Alert rule: %syslog.msg = "@arp-protect@" && %syslog.timestamp = %macros.past_5m
- Alert query: SELECT * FROM syslog WHERE (syslog.device_id = ?) && (syslog.msg = ".*arp-protect.*" && syslog.timestamp = (DATE_SUB(NOW(),INTERVAL 5 MINUTE)) )
- Rule match: no match
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement