Welcome to Pandora FMS Community!

Find answers, ask questions, and connect with our community around the world.

  • BUG in alerting

    Posted by yduma on October 23, 2008 at 02:19

    Hi!

    I think in pandora v2 is a very bib problems with alerting!
    1) in alert, in field_3 I use _agent_, but start receive messages, that agent, that not have telnet to port 8080 is down, and recovered – agent with agent that have. so I think macros _agent_ work with problems
    2) I receive more than 1 time ( in alert seting min =0, max =1) message that something down, and not only one – recovered, or one – something down, and 5 – recovered.
    3) problems with time – downtime – 13:08:22 uptime – 13:08:22 in setting’s – tcp_checks = 6, tcp_time – 60

    can you check this?

    manu replied 16 years, 4 months ago 2 Members · 20 Replies
  • 20 Replies
  • manu

    Member
    October 23, 2008 at 02:55
    0 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    1) Do you mean the macro doesn’t work in the recover email?

    2) min = 0 and max = 1 don’t mean you’ll only get one alert. # Max. Value: De?nes the maximum value for a module. Any value above that threshold will trigger the alert.
    # Min. Value: De?nes the minimum value for a module. Any value below that will trigger the alert. “max.” & “min.” couple are the key values while defining an alert, since they define the range of normal values, out of that range Pandora FMS will trigger the alert.
    So if you want to get just 1 alert you might need to put higher the threshold.

    3) what?

  • yduma

    Member
    October 23, 2008 at 03:16
    2 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    1) yes, for recover don’t work corectly – sometimes work’s, sometimes get another agent name.
    2) I mean Min. number of alerts Value in alert and Max. number of alerts.
    3) I get alert and recovered in same time? Like server was down and after up in same minute.

  • manu

    Member
    October 23, 2008 at 03:20
    0 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    1) Ok, I’m going to test it

    2) Sorry, this is the correct thing:
    # Min. number of alerts: Minimum number of alerts needed to start triggering an alert. Works as a filter, needed to remove false positives.
    # Max. number of alerts: Maximum number of alerts that can be sent consecutively during the same time threshold.

    3) Still don’t understand what you mean.

  • manu

    Member
    October 23, 2008 at 03:27
    0 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    1) It works fine for me. There’s one thing that doesn’t work it’s the macro in the subject, I’m going to file a bug.

  • yduma

    Member
    October 23, 2008 at 04:05
    2 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    and what with 2) and 3)?

  • manu

    Member
    October 23, 2008 at 04:11
    0 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    2) It’s the expected behavior, change the threshold. read the documentation about it.
    3) I don’t know what do you mean.

  • yduma

    Member
    October 23, 2008 at 04:24
    2 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    2) in my settings I have – Min. number of alerts = 0 and Max. number of alerts, but I receive more that 1 letter, and more that 1 recovered letter
    3) in /etc/pandora/pandora_server.conf
    tcp_checks 6
    tcp_timeout 50
    but at 13:24:51 I receive – server down
    at 13:24:52 – server up – WHY?
    as I understand I shouldn’t receive any letter

  • manu

    Member
    October 23, 2008 at 04:42
    0 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    2) again, change the threshold

    3) you have that in the events, right? Do you get those events every hour or every day or when

  • yduma

    Member
    October 23, 2008 at 05:02
    2 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    2)threshold = 1 week

    3) sometimes, for different agent

  • manu

    Member
    October 23, 2008 at 05:08
    0 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    2) do you validate the alert if you do, it’s normal the alert keep coming, try not validating it in a week.

    3) I mean, did the message appear in the events (View Events) with a “System” tag?

  • yduma

    Member
    October 23, 2008 at 05:22
    2 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    2) I never validate alert, for what?
    3) yes

  • manu

    Member
    October 23, 2008 at 05:29
    0 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    2) I’m testing it now

    3) like this?: http://openideas.info/vanilla/comments.php?DiscussionID=634&page=1#Item_3 (read the blue text)

  • manu

    Member
    October 23, 2008 at 05:39
    0 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    2) Works for fine, this is the scenario:

    Min alerts: 0
    Max: 1
    Threshold: 30 minutes

    The alert is fired and I get 1 alert, just one, after 5 or 10, nothing just 1
    If I validate the alert, then I get another one.
    It works fine for me with the latest code, sorry, this time, it ain’t a bug 🙂

  • yduma

    Member
    October 23, 2008 at 05:40
    2 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    3) how get this?

  • manu

    Member
    October 23, 2008 at 05:44
    0 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    3) Did you read what I posted? Are you getting the errors that are shown in that post in blue?

  • yduma

    Member
    October 23, 2008 at 05:44
    2 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    sorry that get you time. maybe something in:
    I make next alert for agent – agent have – telnet 80 and 443 port
    alerts – check 80 port – compound only and same for 443
    1 combined alert for all agent – if all modules in all agent down (all)
    alert combined all_in_host- check alert 80 and 443 port Nand all
    alert combined 80 – check 80 Nand combined all_in_host Nand all
    alert combined 433 – check 443 Nand combined all_in_host nand (all)

    and during this night i receive near 1500 letter’s about 10 real even’t

  • manu

    Member
    October 23, 2008 at 05:50
    0 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    I’m going to test it with same checks you have

    So, to be clear

    1 combined alert with:

    port 80 check
    port 443 check

    If BOTH are down, the combined alert fires, alright?

  • yduma

    Member
    October 23, 2008 at 06:10
    2 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    yes, and alerts – 80 down, alert 443 down

  • manu

    Member
    October 23, 2008 at 06:13
    0 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    alright, I’m going to test it

  • manu

    Member
    October 23, 2008 at 06:27
    0 Karma points
    Community rank: tentacle-noob-1 Tentacle noob
    Like it
    Up
    0
    Down
    Drop it
    ::

    Ok, it works fine for me.

    If I put a threshold in 10, I only get ONE alert within 10 minutes.

    I’ve created those two alerts (compound only) and a combined one with those simple alerts.
    I only got an email

The discussion ‘BUG in alerting’ is closed to new replies.

Start of Discussion
0 of 0 replies June 2018
Now