Re: SYSLOG and SNMP traps analysis and alerting

[email protected]
Newsgroups gmane.org.operators.internet-access
Message-ID <122635952-1241924944-cardhu_decombobulator_blackberry.rim.net-1037946965-@bxe1197.bisx.prod.on.blackberry>
Nagios has log handling and trap handling plugins. 


Sent via BlackBerry from T-Mobile

-----Original Message-----
From: "Frank Bulk" <[email protected]>

Date: Sat, 9 May 2009 21:59:37 
To: <[email protected]>
Subject: RE: SYSLOG and SNMP traps analysis and alerting


Thanks for pointing me to that article.

You address the generation of notices based on certain syslog events, but
I'm missing syslog analysis (strange events, graphing of quantity of certain
types of events over time) and snmp trap translation.  I looked again
snmp-tt, but boy, they're not making it easy.  I want to be able to have a
MIB directory and have the utility generate plain-text output, but looks
like I need to run a translator against each MIB.

Perhaps I need to continue incrementally -- syslog-ng to notify me on
certain types of events, and keep adding tools for each case.  I reviewed
OpenNMS and most of the other opensource graphical tools, they're left
wanting in terms of SNMP trap handling.

Frank

-----Original Message-----
From: [email protected] [mailto:[email protected]] On
Behalf Of Tim Yocum
Sent: Saturday, May 09, 2009 9:07 PM
To: [email protected]
Subject: Re: SYSLOG and SNMP traps analysis and alerting

Hello Frank,

On Sat, May 9, 2009 at 12:27 PM, Frank Bulk <[email protected]> wrote:
[snip]
> I have a syslog-ng in place (as well as NAGIOS and cacti) and I’ve through
> about using snmp-tt, but I still need something to “ingest” my logs and
let
> me know when “strange” things occur.
[snip]

> -       Send me an e-mail [...]
> -       Send me an e-mail  [...]
> -       Send me an e-mail  [...]
> -       Run a script and send an e-mail  [...]
> -       Send me a page  [...]

You are running syslog-ng, so you already have the capability to
define a perl script or similar as a destination that takes filtered
alerts and pipes them into an email. Or an SMS. Or do basically
anything you can write in Perl.

Nate Campi has put a lot of thought into this and more:
http://www.campin.net/newlogcheck.html (thanks, Nate!)

> -       Send me a daily report on how many “denies” have been logged in
our
> BIND logs
>
> -       Search DHCP, CMTS, and eMTA logs for a certain IP or MAC address
>
> -       Graph out over time how many “denies” have been logged for SSH
> “attacks” against my routers

Suddenly it seems your search narrows to some trending work vs.
notifications that you can augment with syslog-ng out of the box.

hth,

- Tim
-- 
Eat sushi frequently. - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list

-- 
Eat sushi frequently. - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list

-- 
Eat sushi frequently. - Avi
[email protected] is the human contact address.
[email protected] is the list posting address.
See below URL for subscribe/unsubscribe and list options:
http://inet-access.net/mailman/listinfo/list
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.