www.delorie.com/gnu/docs/cfengine/cfengine-Anomalies_5.html   search  
 
Buy GNU books!


Anomaly detection with cfenvd and cfenvgraph

[ < ] [ > ]   [ << ] [ Up ] [ >> ]         [Top] [Contents] [Index] [ ? ]

1.4 Starting with anomaly detection

Try importing the following file:

 
#
# cf.environ
#
# Just a test for responses to measured anomalies
#

classes:

 #
 # those hosts we wat to monitor
 #

 anomaly_hosts = ( nexus cube dax ) 

shellcommands:

  nfsd_in_high_dev2::

  "/bin/echo High NFS server access rate 2dev at $(host) value $(value_nfsd_in) \
average $(average_nfsd_in) pm $(stddev_nfsd_in)"


 # ROOT PROCS

  anomaly_hosts.RootProcs_high_dev2::

   "/bin/echo RootProc anomaly high 2 dev on $(host) value $(value_rootprocs) \
average $(average_rootprocs) pm $(stddev_rootprocs)"

 # USER PROCS

 anomaly_hosts.UserProcs_high_dev2::
 
   "/bin/echo UserProc anomaly high 2 dev on $(host) value $(value_userprocs) \
average $(average_userprocs) pm $(stddev_userprocs)"
     
 anomaly_hosts.UserProcs_high_anomaly::
 
   "/bin/echo UserProc anomaly high 3 dev!! on $(host)"
    
 # WWW IN
 
 anomaly_hosts.www_in_high_dev2::
 
   "/bin/echo Incoming www anomaly high 2 dev on $(host) - value $(value_www_in) \
average $(average_www_in) pm $(stddev_www_in)" 

 anomaly_hosts.www_in_high_anomaly::
 
   "/bin/echo Incoming www anomaly high anomaly dev!! on $(host) - value \
$(value_www_in) average $(average_www_in) pm $(stddev_www_in)" 
  
 # SMTP IN
 
 anomaly_hosts.smtp_in_high_dev2::
 
   "/bin/echo Incoming smtp anomaly high 2 dev on $(host)  value $(value_smtp_in)\
 average  $(average_smtp_in) pm $(stddev_smtp_in)" 

 anomaly_hosts.smtp_in_high_anomaly::
 
   "/bin/echo Incoming smtp anomaly high anomaly !! on $(host)  value $(value_smtp_in)\
 average  $(average_smtp_in) pm $(stddev_smtp_in)"
 
 # SMTP OUT
 
 anomaly_hosts.smtp_out_high_dev2::
 
   "/bin/echo Outgoing smtp anomaly high 2 dev on $(host) value $(value_smtp_out) \
average  $(average_smtp_out) pm $(stddev_smtp_out)"
 
 anomaly_hosts.smtp_out_high_anomaly::
 
   "/bin/echo Outgoing smtp anomaly high anomaly dev!! on $(host) value \
$(value_smtp_out) average $(average_smtp_out) pm $(stddev_smtp_out)"
 
 # SAMBA

 anomaly_hosts.netbiosssn_in_high_dev2::

   "/bin/echo SAMBA access high 2 on $(host) value $(value_netbiosssn_in)\
 average $(average_netbiosssn_in) pm $(stddev_netbiosssn_in)"    


  webmaster   donations   bookstore     delorie software   privacy  
  Copyright 2003   by The Free Software Foundation     Updated Jun 2003