# - verdi: pg upgrade, openvpn
# - mundy: salinfo_decode
# - puccini: mailgraph
-# -
-# - piatti
-# - tartini
-#sarge:
-# - spontini
+# - lebrun: ippl
# down:
# - ravel
address: 82.195.75.126
parents: gw-HP-ftc
hostgroups: routing-infrastructure
+ contacts: joerg, bzed
gw-HP-ftc:
address: 192.25.206.1
parents: samosa
address: 195.49.152.190
parents: gw-HP-ftc
hostgroups: routing-infrastructure
+ contacts: bzed
gw-freenet:
address: 62.104.23.249
parents: gw-HP-ftc
address: 193.62.202.18
parents: gw-HP-ftc
hostgroups: routing-infrastructure
+ contacts: tjrc1
gw-cst:
address: 213.188.99.215
parents: gw-HP-ftc
parents: gw-HP-ftc
hostgroups: routing-infrastructure
gw-1und1:
- address: 195.20.247.53
+ address: 195.20.247.54
parents: gw-HP-ftc
hostgroups: routing-infrastructure
+ contacts: joerg
gw-blackcat:
address: 193.201.200.129
parents: gw-HP-ftc
hostgroups: routing-infrastructure
gw-xandros:
- address: 142.46.212.33
+ address: 67.210.160.81
parents: gw-HP-ftc
hostgroups: routing-infrastructure
gw-nmmn:
address: 65.173.90.18
parents: gw-HP-ftc
hostgroups: routing-infrastructure
+ gw-ubc:
+ address: 137.82.84.41
+ parents: gw-HP-ftc
+ hostgroups: routing-infrastructure
+ contacts: lfilipoz
+ gw-carnet:
+ address: 161.53.160.1
+ parents: gw-HP-ftc
+ hostgroups: routing-infrastructure
+ gw-telegraaf:
+ address: 82.94.249.153
+ parents: gw-HP-ftc
+ hostgroups: routing-infrastructure
+ gw-helsinki:
+ address: 128.214.173.25
+ parents: gw-HP-ftc
+ hostgroups: routing-infrastructure
+ contacts: holger
samosa:
address: 192.25.206.57
address: 192.25.206.15
parents: samosa
hostgroups: computers, buildd, sw-raid, single-cpu
+ contacts: dannf
penalosa:
address: 192.25.206.68
parents: samosa
hostgroups: computers, buildd, sw-raid, single-cpu
+ contacts: dannf
mundy:
address: 192.25.206.62
parents: samosa
address: 192.25.206.11
parents: samosa
hostgroups: computers, porterbox, bind9-hosts
+ merulo:
+ address: 192.25.206.58
+ parents: samosa
+ hostgroups: computers, porterbox
bartok:
address: 82.195.75.91
parents: gw-man-da
hostgroups: computers, service, syslog-ng-hosts, postfix-hosts, dl385
+ contacts: joerg, bzed
sperger:
address: 82.195.75.98
parents: gw-man-da
hostgroups: computers, porterbox, sw-raid
+ contacts: bzed
agricola:
address: 82.195.75.86
parents: gw-man-da
- hostgroups: computers, porterbox, sw-raid, single-cpu
+ hostgroups: computers, porterbox, sw-raid, single-cpu, lenny
+ contacts: bzed
arcadelt:
address: 82.195.75.87
parents: gw-man-da
- hostgroups: computers, buildd, sw-raid, single-cpu
+ hostgroups: computers, buildd, sw-raid, single-cpu, lenny
+ contacts: bzed
liszt:
address: 82.195.75.100
parents: gw-man-da
- hostgroups: computers, service, apache2-hosts, bind9-hosts, postfix-hosts, heavy-postfix, dl385
+ hostgroups: computers, service, apache2-hosts, bind9-hosts, postfix-hosts, heavy-postfix, amavis-hosts, dl385
+ contacts: bzed
master:
address: 70.103.162.29
murphy:
address: 70.103.162.31
parents: gw-brainfood
- hostgroups: computers, general, apache2-hosts, bind9-hosts, postfix-hosts
+ hostgroups: computers, general, apache2-hosts, bind9-hosts, postfix-hosts, dl380
ries:
address: 128.148.34.103
argento:
address: 195.49.152.174
parents: gw-dg-i.net
- hostgroups: computers, buildd, sw-raid, single-cpu
+ hostgroups: computers, buildd, sw-raid, single-cpu, lenny
+ contacts: bzed
pergolesi:
address: 62.104.23.252
raptor:
address: 195.243.109.162
parents: gw-topalis
- hostgroups: computers, porterbox
+ hostgroups: computers, porterbox, postfix-hosts
albeniz:
address: 193.62.202.27
parents: gw-sanger
hostgroups: computers, porterbox, sw-raid
+ contacts: tjrc1
goetz:
address: 193.62.202.26
parents: gw-sanger
hostgroups: computers, buildd, sw-raid
+ contacts: tjrc1
escher:
address: 213.188.99.215
address: 72.66.115.54
parents: gw-frost
hostgroups: computers, buildd
+ contacts: sfrost
puccini:
address: 87.106.4.56
parents: gw-1und1
hostgroups: computers, service, apache2-hosts, bind9-hosts, postfix-hosts, heavy-postfix, amavis-hosts
+ contacts: joerg
caballero:
address: 193.201.200.200
parents: gw-blackcat
- hostgroups: computers, buildd, sw-raid
+ hostgroups: computers, buildd, sw-raid, bind9-hosts
elara:
- address: 142.46.212.46
+ address: 67.210.160.90
parents: gw-xandros
hostgroups: deadslow
europa:
- address: 142.46.212.46
+ address: 67.210.160.89
parents: gw-xandros
hostgroups: deadslow
address: 217.114.76.82
parents: gw-nmmn
hostgroups: deadslow
+ contacts: luk
crest:
address: 217.114.76.83
parents: gw-nmmn
hostgroups: deadslow
+ contacts: luk
kassia:
address: 130.89.175.54
allegri:
address: 157.193.39.233
parents: gw-HP-ftc
- hostgroups: computers, buildd, postfix-hosts, sw-raid, single-cpu
+ hostgroups: computers, buildd, postfix-hosts, sw-raid, single-cpu, lenny
+ contacts: luk
agnesi:
address: 65.173.90.83
parents: gw-agnesi
hostgroups: deadslow
+ spontini:
+ address: 137.82.84.42
+ parents: gw-ubc
+ hostgroups: computers, buildd
+ contacts: lfilipoz
+
+ lebrun:
+ address: 161.53.160.165
+ parents: gw-carnet
+ hostgroups: computers, buildd
+
+ tartini:
+ address: 82.94.249.158
+ parents: gw-telegraaf
+ hostgroups: computers, sw-raid
+
+ piatti:
+ address: 193.167.161.225
+ parents: gw-helsinki
+ hostgroups: computers, postfix-hosts, dl385
+ contacts: holger
+
#############################
# host groups
#
alias: Hosts with only one CPU
private: 1
+ lenny:
+ alias: Hosts running lenny, not etch
+ private: 1
+
syslog-ng-hosts:
alias: hosts running syslog-ng instead of sysklogd
private: 1
alias: "hosts running the full mail stuff, including clamav, SA, and greylistd"
private: 1
heavy-postfix:
- alias: "postfix hosts running the full mail stuff, including clamav, SA, postgrey, amavis, policyd-weight"
+ alias: "postfix hosts running the full mail stuff, including clamav, SA, postgrey, policyd-weight"
private: 1
apache2-hosts:
alias: hosts running apache2
alias: secondary IP addresses
private: 1
+
+#############################
+# servicegroups
+#############################
+servicegroups:
+ diskspace:
+ alias: diskusage checks
+ buildd:
+ alias: buildd checks
+ raid:
+ alias: raid checks
+ kernel:
+ alias: kernel checks
+ weaksshkeys:
+ alias: weak ssh keys
+ apt:
+ alias: apt upgrade status
+ security:
+ alias: security
+ servicegroup_members: apt, weaksshkeys, kernel
+
#############################
# services
#############################
####
-
name: disk usage - all
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 90 95"
hostgroups: computers
-
name: disk usage on /
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 80 90 /"
hostgroups: computers
-
name: disk usage on /boot
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 75 85 /boot"
- hosts: sperger, rietz, steffani, penalosa, peri, albeniz, escher, goetz, mayer, mayr, paer
+ hosts: sperger, rietz, steffani, penalosa, peri, albeniz, escher, goetz, mayer, mayr, paer, spontini, tartini
-
name: disk usage on /var
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /var"
- hosts: bartok, samosa, raff, lobos, villa, gluck, saens, escher, voltaire, puccini
+ hosts: bartok, samosa, raff, lobos, villa, gluck, saens, escher, voltaire, puccini, lebrun, tartini
-
name: disk usage on /org
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 80 90 /org"
- hosts: bartok, sperger, samosa, raff, lobos, villa, steffani, saens, pergolesi, verdi, puccini
+ hosts: bartok, sperger, samosa, raff, lobos, villa, steffani, saens, pergolesi, verdi, puccini, spontini
-
name: disk usage on /org
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 90 95 /org"
hosts: merkel
-
name: disk usage on /srv
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 80 90 /srv"
- hosts: agricola, arcadelt, argento, allegri
+ hosts: agricola, arcadelt, argento, allegri, tartini
-
name: disk usage on /org/scratch
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 80 90 /org/scratch"
hosts: merkel
-
name: disk usage on /tmp
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 60 80 /tmp"
- hosts: samosa, raff, gluck, saens, escher, puccini
+ hosts: samosa, raff, gluck, saens, escher, puccini, merkel, tartini
-
name: disk usage on /usr
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /usr"
- hosts: samosa, raff, lobos, villa, gluck, saens, pergolesi, puccini
+ hosts: samosa, raff, lobos, villa, gluck, saens, pergolesi, puccini, merulo, tartini
-
name: disk usage on /home
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /home"
- hosts: raptor, escher, voltaire
+ hosts: raptor, escher, voltaire, lebrun
-
name: disk usage on /home
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 90 95 /home"
hosts: gluck
-
name: disk usage on /chroot
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /chroot"
hosts: raptor
-
name: disk usage on /mnt/hdc
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /mnt/hdc"
hosts: voltaire
+ -
+ name: disk usage on /mnt/sdb1
+ servicegroups: diskspace
+ nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /mnt/sdb1"
+ hosts: spontini
-
name: disk usage on /x
+ servicegroups: diskspace
nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /x"
hosts: caballero
############ All Computers ############
####
- #-
- # name: apt - security updates
- # nrpe: "/usr/local/bin/nagios-check-apt-updates --warnifupdates"
- # hostgroups: computers
- # normal_check_interval: 480
- # notification_interval: 480
- # max_check_attempts: 4
- # retry_check_interval: 12
+ -
+ name: apt - security updates
+ servicegroups: apt
+ nrpe: "/usr/lib/nagios/plugins/dsa-check-statusfile /var/cache/dsa/nagios/apt"
+ hostgroups: computers
+ normal_check_interval: 360
####
-
name: backup
max_check_attempts: 2
retry_check_interval: 5
+ ####
+ -
+ name: running kernel
+ servicegroups: kernel
+ nrpe: "/usr/lib/nagios/plugins/dsa-check-running-kernel"
+ hostgroups: computers
+ normal_check_interval: 180
+ retry_check_interval: 5
+
####
-
name: users
hostgroups: computers
depends: process - sshd
normal_check_interval: 60
+ notification_interval: 1440
-
name: "network service - sshd"
check: dsa_check_ssh_port!2260
hosts: agnesi
normal_check_interval: 180
+ -
+ name: "network service - sshd - 443"
+ check: dsa_check_ssh_port!443
+ hosts: gluck
+ normal_check_interval: 180
+
+ -
+ name: "network service - sshd - version"
+ check: "dsa_check_ssh_port_version!22!OpenSSH_4.3p2 Debian-9etch2"
+ depends: network service - sshd
+ hostgroups: computers, deadslow
+ excludehosts: agnesi
+ excludehostgroups: lenny
+ normal_check_interval: 360
+ -
+ name: "network service - sshd - version"
+ check: "dsa_check_ssh_port_version!22!OpenSSH_4.7p1 Debian-9"
+ depends: network service - sshd
+ hostgroups: lenny
+ normal_check_interval: 360
+ -
+ name: "network service - sshd - version - 2260"
+ check: "dsa_check_ssh_port_version!2260!OpenSSH_4.3p2 Debian-9etch2"
+ depends: network service - sshd - 2260
+ hosts: agnesi
+ normal_check_interval: 360
+ #
+ -
+ name: ssh - weak keys
+ servicegroups: weaksshkeys
+ nrpe: "/usr/lib/nagios/plugins/dsa-check-statusfile /var/cache/dsa/nagios/weak-ssh-keys"
+ hostgroups: computers
+ normal_check_interval: 360
####
-
name: network service - nrpe
check: check_tcp!5666
hostgroups: computers
- max_check_attempts: -1
+ max_check_attempts: -2
+ notification_interval: 1440
-
name: process - nrpe
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:25 -c 1: -u nagios -C nrpe -a '/usr/sbin/nrpe -c /etc/nagios/nrpe.cfg -d'"
hostgroups: computers
+ max_check_attempts: -1
depends: network service - nrpe
###
-
###
-
name: process - cron
- nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C cron -a /usr/sbin/cron"
+ nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:2 -c 1: -u root -C cron -a /usr/sbin/cron"
hostgroups: computers
###
depends: process - postfix - master
-
name: process - postfix - anvil
- nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postfix -C anvil -a 'anvil -l -t unix -u'"
+ nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:1 -c 0: -u postfix -C anvil -a 'anvil -l -t unix -u'"
hostgroups: postfix-hosts
depends: process - postfix - master
-
name: process - postfix - smtpd
- nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:20 -c 0:50 -u postfix -C smtpd -a 'smtpd -n smtp -t inet -u -c'"
+ nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:40 -c 0:90 -u postfix -C smtpd -a 'smtpd -n smtp -t inet -u -c'"
hostgroups: postfix-hosts
excludehosts: liszt
depends: process - postfix - master
name: network service - smtp
check: dsa_check_smtp
hostgroups: postfix-hosts
- excludehosts: verdi, kassia, allegri
+ excludehosts: verdi, kassia, allegri, raptor, piatti
depends: process - postfix - master
-
name: network service - smtp - port 2025
check: dsa_check_smtp_port!2025
- hosts: verdi, kassia, murphy, allegri
+ hosts: verdi, kassia, murphy, allegri, piatti
+ depends: process - postfix - master
+ -
+ name: network service - smtp - port 8080
+ check: dsa_check_smtp_port!8080
+ hosts: murphy, piatti
+ depends: process - postfix - master
+ -
+ name: network service - smtp - port 2025
+ remotecheck: /usr/lib/nagios/plugins/check_smtp -t 40 -H $HOSTADDRESS$ -p 2025
+ runfrom: murphy
+ hosts: raptor
depends: process - postfix - master
-
nrpe: "/usr/lib/nagios/plugins/check_http -H localhost -p 465 -S -C 14 -t 45"
hostgroups: postfix-hosts
depends: process - postfix - master
- normal_check_interval: 1440
+ normal_check_interval: 120
-
name: setup - debian-admin in etc aliases
nrpe: "/usr/lib/nagios/plugins/dsa-check-da-in-aliases"
hostgroups: computers
- normal_check_interval: 1440
+ normal_check_interval: 120
+ -
+ name: setup - ud-ldap freshness
+ nrpe: "/usr/lib/nagios/plugins/dsa-check-udldap-freshness"
+ hostgroups: computers
###
-
name: process - uptimed
hostgroups: computers
excludehostgroups: single-cpu
-
- name: unwanted process - named
+ name: unwanted process - irqbalance
nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C irqbalance"
hostgroups: single-cpu
###
-
name: process - mdadm monitor
+ servicegroups: raid
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C mdadm -a '/sbin/mdadm --monitor --pid-file /var/run/mdadm/monitor.pid --daemonise --scan'"
hostgroups: sw-raid
-
name: RAID - sw raid
+ servicegroups: raid
nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-sw"
hostgroups: sw-raid
###
-
name: process - cpqarrayd
+ servicegroups: raid
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C cpqarrayd -a '/usr/sbin/cpqarrayd'"
hostgroups: dl385, dl380, dl360
-
name: RAID - arrayprobe
+ servicegroups: raid
nrpe: "sudo /usr/bin/arrayprobe"
hostgroups: dl385, dl380, dl360
+ -
+ name: HW - hpacucli status
+ servicegroups: raid
+ nrpe: "/usr/lib/nagios/plugins/dsa-check-hpacucli"
+ hostgroups: dl385, dl380, dl360
+ ###
+ -
+ name: RAID - DAC960
+ servicegroups: raid
+ nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-dac960"
+ hosts: verdi
+ ###
+ -
+ name: RAID - 3ware
+ servicegroups: raid
+ nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-3ware"
+ hosts: puccini
+ ###
+ -
+ name: RAID - MPT
+ servicegroups: raid
+ nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-mpt"
+ hosts: master
###
-
depends: rietz:process - xinetd
###
- -
- name: process - nagios1
- nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u nagios -C nagios -a '/usr/sbin/nagios -d /etc/nagios/nagios.cfg'"
- hosts: samosa
-
name: process - nagios3
# there is always one extra process per check currently running..
####
-
name: process - debianqueued
- nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u dak -C debianqueued -a '/usr/bin/perl -w ./debianqueued'"
+ nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u dak -C debianqueued"
hosts: ries
###
depends: process - postresql81 - master
####
- # XXX is this needed
+ -
+ name: process - xenconsoled
+ nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C xenconsoled -a 'xenconsoled'"
+ hosts: piatti
+ -
+ name: process - xenstored
+ nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C xenstored -a '/usr/lib/xen-3.0.3-1/bin/xenstored --pid-file /var/run/xenstore.pid'"
+ hosts: piatti
+ -
+ name: process - xend
+ nrpe: "/usr/lib/nagios/plugins/check_procs -w 2:2 -c 2: -u root -C python -a 'python /usr/lib/xen-3.0.3-1/bin/xend start'"
+ hosts: piatti
+
+ ####
+ # XXX is this needed?
-
name: process - snmpd
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u snmp -C snmpd -a '/usr/sbin/snmpd -Lsd -Lf /dev/null -u snmp -I -smux -p /var/run/snmpd.pid 127.0.0.1'"
###
-
name: process - buildd
+ servicegroups: buildd
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u buildd -C buildd '/usr/bin/perl /usr/bin/buildd'"
hostgroups: buildd