SYSLOG and SNMP traps analysis and alerting
"Frank Bulk" <[email protected]>
| Newsgroups | gmane.org.operators.internet-access |
|---|---|
| Message-ID | <!&!AAAAAAAAAAAuAAAAAAAAAKTyXRN5/+lGvU59a+P7CFMBAN6gY+ZG84BMpVQcAbDh1IQAAAATbSgAABAAAAAltkxTTdmOR7ixzGfs/[email protected]> |
There are a lot of things I can poll using SNMP or obtain from the CLI using Perl-fu, but there's other information that comes in via syslog and SNMP traps. I have a syslog-ng in place (as well as NAGIOS and cacti) and I've through about using snmp-tt, but I still need something to "ingest" my logs and let me know when "strange" things occur. For example: - Send me an e-mail when the CMTS logs an event that's never happened before, but ignore those that are "regular" - Send me an e-mail when a switch los an event that's never happened before - Send me an e-mail when an Alvarion AU generates a trap when a threshold has been reached - Run a script and send an e-mail when an eMTA syslogs "low battery" - Send me a page when an OSPF event occurs on our edge routers - Send me a daily report on how many "denies" have been logged in our BIND logs - Search DHCP, CMTS, and eMTA logs for a certain IP or MAC address - Graph out over time how many "denies" have been logged for SSH "attacks" against my routers I've looked at the web pages of two products, Sawmill and Paglo, but looking for some input from the group here on these and other (free) products that can do the trick for me. Regards, Frank -- Eat sushi frequently. - Avi [email protected] is the human contact address. [email protected] is the list posting address. See below URL for subscribe/unsubscribe and list options: http://inet-access.net/mailman/listinfo/list