[hobbit] No alerts propagating...
David Gore
David.Gore at mci.com
Sun Jan 30 00:39:01 CET 2005
RULES:
HOST=rchimpm1,rsoimpm1 COLOR=red,yellow
MAIL somebody at somehost.com DURATION>15
HOST=lismore
SCRIPT /export/home/rbaldwin/hobbit.sh PAGE RECOVERED REPEAT=8h
DUMP:
HOST=rchimpm1,rsoimpm1 COLOR=yellow,red
MAIL page_somebody at somehost.com REPEAT=30 COLOR=yellow,red
DURATION>15
HOST=lismore
SCRIPT /export/home/rbaldwin/hobbit.sh PAGE FORMAT=SCRIPT
REPEAT=480 RECOVERED
debug:
2005-01-29 22:48:41 criteriamatch rchimpm1:procs
rchimpm1,rsoimpm1:(NULL):(NULL)
2005-01-29 22:48:41 Checking explicit color setting 10000000060 against
4 gives 1
2005-01-29 22:48:41 Found a first matching rule
2005-01-29 22:48:41 criteriamatch rchimpm1:procs (NULL):(NULL):(NULL)
2005-01-29 22:48:41 failed minduration 0<900
so far so good...
2005-01-29 23:32:38 Got page message from cosimpm1:rds
2005-01-29 23:32:38 0 alerts to go
2005-01-29 23:33:38 0 alerts to go
Nothing in between, so it started well and didn't go anywhere
bummer.
David Gore wrote:
> COLOR=red
> MAIL somebody at somehost.com REPEAT=8h DURATION>15
>
> Is this a possible rule, or do you need BOTH a HOST and a SERVICE for
> ANY rule? Or do you need at least one, HOST or a SERVICE? Can I have a
> rule for ALL red alarms? This is running on Solaris 9.
>
> 2005-01-29 22:48:41 criteriamatch rchimpm1:procs
> rchimpm1,rsoimpm1:(NULL):(NULL)
> 2005-01-29 22:48:41 Checking explicit color setting 10000000060 against
> 4 gives 1
> 2005-01-29 22:48:41 Found a first matching rule
> 2005-01-29 22:48:41 criteriamatch rchimpm1:procs (NULL):(NULL):(NULL)
> 2005-01-29 22:48:41 failed minduration 0<900
>
> David Gore (v965-3670)
> Enhanced Technology Support (ETS)
> Network Management Systems (NMS)
> IMPACT Transport Team Lead - SCSA, SCNA
> Page: 1-800-PAG-eMCI pin 1406090
> Vnet: 965-3676
>
>
> David Gore wrote:
>
>>
>> Ok, the alerts are driving me mad. What I would like to do is send out
>> a mail/page for any alert that turns red and is red for 15 minutes or
>> longer. I assumed DURATION>15 would work? DURATION>15m results in
>> rather large number by the way that may indicate a bug, 'h' works and
>> leaving off 'm' seems to parse OK. None of these work, and there is
>> nothing in ~/log/page.log. Here are our rules and a dump.
>>
>> COLOR=red
>> MAIL somebody at somehost.com REPEAT=8h
>>
>> SERVICE=conn,procs,disk,vmem EXHOST=dante,cayhp2,cayhp3
>> MAIL somebody at somehost.com REPEAT=8h DURATION>15
>>
>> HOST=dante,cayhp2,cayhp3 COLOR=red
>> MAIL somebody-different at somehost.com REPEAT=1d
>>
>> HOST=nmsbb-get SERVICE=pri-1 COLOR=red
>> MAIL somebody at somehost.com REPEAT=8h DURATION<29
>>
>> COLOR=red
>> SCRIPT /export/home/rbaldwin/hobbit.sh
>>
>> hobbit at nmsbb-get ~/server> ./bin/bbcmd --env=etc/hobbitserver.cfg
>> hobbitd_alert --dump-config
>>
>> COLOR=red
>> MAIL somebody at somehost.com REPEAT=480
>>
>> EXHOST=dante,cayhp2,cayhp3 SERVICE=conn,procs,disk,vmem
>> MAIL somebody at somehost.com REPEAT=480 DURATION>15
>>
>> HOST=dante,cayhp2,cayhp3 COLOR=red
>> MAIL somebody-different at somehost.com REPEAT=1440
>>
>> HOST=nmsbb-get SERVICE=pri-1 COLOR=red
>> MAIL somebody at somehost.com REPEAT=480 COLOR=red DURATION<29
>>
>> COLOR=red
>>
>> We don't mind re-simplyfying just for paging on ALL red alarms that
>> are RED for 15 minutes or longer and wacking all the other rules that
>> do not work. Thanks for any help.
>>
>>
>> ~ David Gore
>>
>
> To unsubscribe from the hobbit list, send an e-mail to
> hobbit-unsubscribe at hswn.dk
>
>
More information about the Xymon
mailing list