uploadqueue hostgroup. chopin is part of it, klecker not anymore
[mirror/dsa-nagios.git] / config / nagios-master.cfg
index 2e9a0f2..0bf9f73 100644 (file)
@@ -10,7 +10,6 @@
 #  - *: check munin stats collection works
 #  - *: check backups are successful
 #  - *: unwanted: network: auth, discard, daytime, time (on some), cvs-pserver, rsync (on some), ftp (on some), http (on some)
-#  - verdi: pg upgrade, openvpn
 #  - mundy: salinfo_decode
 
 # down:
@@ -27,6 +26,11 @@ servers:
     parents: gw-HP-ftc
     hostgroups: routing-infrastructure
     contacts: joerg, bzed
+  gw-man-da2:
+    address: 82.195.75.46
+    parents: gw-man-da
+    hostgroups: routing-infrastructure
+    contacts: joerg, bzed
   gw-HP-ftc:
     address: 192.25.206.1
     parents: spohr
@@ -77,10 +81,6 @@ servers:
     parents: gw-HP-ftc
     hostgroups: routing-infrastructure
     contacts: tjrc1
-  gw-lrz:
-    address: 129.187.0.150
-    parents: gw-HP-ftc
-    hostgroups: routing-infrastructure
   gw-frost:
     address: 130.81.242.195
     parents: gw-HP-ftc
@@ -111,7 +111,7 @@ servers:
   #  parents: gw-HP-ftc
   #  hostgroups: routing-infrastructure
   gw-agnesi:
-    address: 65.173.90.18
+    address: 65.173.90.22
     parents: gw-HP-ftc
     hostgroups: routing-infrastructure
   gw-ubc:
@@ -119,6 +119,11 @@ servers:
     parents: gw-HP-ftc
     hostgroups: routing-infrastructure
     contacts: lfilipoz
+  gw-ubcnew:
+    address: 206.12.19.254
+    parents: gw-HP-ftc
+    hostgroups: routing-infrastructure
+    contacts: lfilipoz
   gw-carnet:
     address: 161.53.160.1
     parents: gw-HP-ftc
@@ -153,13 +158,17 @@ servers:
     parents: gw-HP-ftc
     hostgroups: routing-infrastructure
   gw-esiee:
-    address: 147.215.2.249
+    address: 195.220.83.13
     parents: gw-HP-ftc
     hostgroups: routing-infrastructure
   gw-ghent:
     address: 193.191.17.50
     parents: gw-HP-ftc
     hostgroups: routing-infrastructure
+  gw-anu:
+    address: 150.203.164.38
+    parents: gw-HP-ftc
+    hostgroups: routing-infrastructure
 
   global:
     hostgroups: notacomputer
@@ -169,15 +178,11 @@ servers:
   samosa:
     address: 192.25.206.57
     parents: spohr
-    hostgroups: computers, service, dl380, lenny, hassrvfs, hasbootfs, acpid-hosts, ulogd-hosts
+    hostgroups: computers, service, dl380, lenny, hassrvfs, hasbootfs, acpid-hosts, ulogd-hosts, nfs-client, postgres84-hosts
   raff:
     address: 192.25.206.59
     parents: spohr
     hostgroups: computers, no-udev, service, dl380, apache2-hosts, bind9-hosts, rsyncd-hosts, heavy-exim, ulogd-hosts, nfs-client, lenny, hasvarfs, hasusrfs
-  gluck:
-    address: 192.25.206.10
-    parents: spohr
-    hostgroups: computers, no-udev, general, dl380, ulogd-hosts, lenny, hassrvfs 
   merkel:
     address: 192.25.206.16
     parents: spohr
@@ -196,12 +201,12 @@ servers:
   peri:
     address: 192.25.206.15
     parents: spohr
-    hostgroups: computers, buildd, sw-raid, hasbootfs, lenny
+    hostgroups: computers, buildd, sw-raid, hasbootfs, lenny, single-cpu
     contacts: dannf
   penalosa:
     address: 192.25.206.68
     parents: spohr
-    hostgroups: computers, buildd, sw-raid, hasbootfs, lenny
+    hostgroups: computers, buildd, hasbootfs, lenny
     contacts: dannf
   mundy:
     address: 192.25.206.62
@@ -227,8 +232,8 @@ servers:
   #  hostgroups: computers, porterbox, single-cpu, no-samhain, hasbootfs, hassrvfs, lenny, hasvarfs, hasusrfs
   #  contacts: bzed
   sperger:
-    address: 82.195.75.98
-    parents: gw-man-da
+    address: 82.195.75.34
+    parents: gw-man-da2
     hostgroups: computers, porterbox, sw-raid, hasbootfs, lenny
     contacts: bzed
   agricola:
@@ -271,6 +276,10 @@ servers:
     address: 82.195.75.107
     parents: unger
     hostgroups: computers, service, lenny, hasbootfs, apache2-hosts, single-cpu, rsyncd-hosts
+  byrd:
+    address: 82.195.75.101
+    parents: unger
+    hostgroups: computers, service, lenny, hasbootfs, hassrvfs, postgres84-hosts
 
   master:
     address: 70.103.162.29
@@ -281,10 +290,11 @@ servers:
     parents: gw-brainfood
     hostgroups: computers, general, dl380, acpid-hosts, lenny, buildd, hasbootfs, hassrvfs
 
+
   ries:
     address: 128.148.34.103
     parents: gw-brown.edu
-    hostgroups: computers, service, apache2-hosts, bind9-hosts, ftpd-hosts, dl385, rsyncd-hosts, postgres83-hosts, heavy-exim, acpid-hosts, lenny
+    hostgroups: computers, service, apache2-hosts, bind9-hosts, ftpd-hosts, dl385, rsyncd-hosts, postgres83-hosts, heavy-exim, acpid-hosts, lenny, uploadqueue
 
   mayer:
     address: 140.211.166.78
@@ -306,6 +316,10 @@ servers:
     address: 140.211.166.44
     parents: rietz
     hostgroups: secondary-IPs
+  zee:
+    address: 140.211.166.16
+    parents: gw-osuosl
+    hostgroups: computers, porterbox, lenny, hassrvfs, hasbootfs
 
   villa:
     address: 212.211.132.32
@@ -315,6 +329,10 @@ servers:
     address: 212.211.132.250
     parents: gw-scanplus-lobos
     hostgroups: computers, service, apache2-hosts, ftpd-hosts, rsyncd-hosts, dl380, lenny, hasvarfs, hasusrfs
+  gluck:
+    address: 150.203.164.38
+    parents: gw-anu
+    hostgroups: computers, service, apache2-hosts, ftpd-hosts, rsyncd-hosts, dl380, lenny, no-udev, hassrvfs, acpid-hosts
 
   steffani:
     address: 128.31.0.36
@@ -331,7 +349,7 @@ servers:
   senfl:
     address: 128.31.0.51
     parents: gw-mit-csail
-    hostgroups: computers, service, lenny, dl360, acpid-hosts, hassrvfs, ulogd-hosts, apache2-hosts
+    hostgroups: computers, service, lenny, dl360, acpid-hosts, hassrvfs, ulogd-hosts, apache2-hosts, rsyncd-hosts
   carver:
     address: 128.31.0.50
     parents: gw-mit-csail
@@ -340,7 +358,7 @@ servers:
   klecker:
     address: 194.109.137.218
     parents: gw-xs4all
-    hostgroups: computers, service, apache2-hosts, ftpd-hosts, rsyncd-hosts, bind9-hosts, dl385, postgres83-hosts, heavy-exim, lenny
+    hostgroups: computers, service, apache2-hosts, ftpd-hosts, rsyncd-hosts, bind9-hosts, dl385, heavy-exim, lenny
 
   saens:
     address: 128.101.240.212
@@ -356,7 +374,7 @@ servers:
   widor:
     address: 93.94.130.161
     parents: gw-dg-i.net
-    hostgroups: computers, apache2-hosts, sw-raid, single-cpu, lenny, acpid-hosts
+    hostgroups: computers, apache2-hosts, sw-raid, lenny, acpid-hosts
     contacts: bzed
 
   pergolesi:
@@ -382,11 +400,6 @@ servers:
     hostgroups: computers, porterbox, sw-raid, lenny
     contacts: tjrc1
 
-  verdi:
-    address: 192.54.42.193
-    parents: gw-lrz
-    hostgroups: computers, service, apache2-hosts, ftpd-hosts, rsyncd-hosts, postgres81-hosts, postfix-hosts
-
   voltaire:
     address: 72.66.115.54
     parents: gw-frost
@@ -415,11 +428,15 @@ servers:
   chopin:
     address: 195.20.242.124
     parents: schumann
-    hostgroups: computers, ulogd-hosts, lenny, hassrvfs
+    hostgroups: computers, service, apache2-hosts, ulogd-hosts, lenny, hassrvfs, hasbootfs, rsyncd-hosts, uploadqueue
   geo3:
     address: 195.20.242.125
     parents: schumann
     hostgroups: computers, service, lenny, hasbootfs, single-cpu, bind9-hosts
+  soler:
+    address: 195.20.242.126
+    parents: schumann
+    hostgroups: computers, service, lenny, hasbootfs, hassrvfs
 
   caballero:
     address: 193.201.200.200
@@ -443,7 +460,7 @@ servers:
     address: 130.89.149.226
     parents: kassia
     hostgroups: secondary-IPs
-  kassia4:
+  kassia-volatile:
     address: 130.89.149.227
     parents: kassia
     hostgroups: secondary-IPs
@@ -455,7 +472,7 @@ servers:
     contacts: luk
 
   agnesi:
-    address: 65.173.90.83
+    address: 67.233.102.241
     parents: gw-agnesi
     hostgroups: deadslow, lenny
 
@@ -465,13 +482,21 @@ servers:
     hostgroups: computers, buildd, hasbootfs, lenny
     contacts: lfilipoz
   ravel:
-    address: 137.82.84.66
-    parents: gw-ubc
-    hostgroups: computers, general, dl385, apache2-hosts, acpid-hosts, ftpd-hosts, hasbootfs, lenny, nfs-server, rsyncd-hosts
+    address: 206.12.19.5
+    parents: gw-ubcnew
+    hostgroups: computers, general, dl385, apache2-hosts, acpid-hosts, ftpd-hosts, hasbootfs, lenny, nfs-server, rsyncd-hosts, bind9-hosts, uploadqueue
   dijkstra:
     address: 137.82.84.70
     parents: gw-ubc
-    hostgroups: computers, bl460, acpid-hosts, lenny
+    hostgroups: computers, bl460, acpid-hosts, lenny, ulogd-hosts
+  luchesi:
+    address: 206.12.19.214
+    parents: gw-ubcnew
+    hostgroups: computers, bl460, acpid-hosts, lenny, ulogd-hosts
+  wolkenstein:
+    address: 137.82.84.89
+    parents: dijkstra
+    hostgroups: computers, lenny, hasbootfs, hassrvfs
   brahms:
     address: 137.82.84.74
     parents: dijkstra
@@ -487,18 +512,34 @@ servers:
   valente:
     address: 137.82.84.76
     parents: dijkstra
-    hostgroups: computers, lenny, hasbootfs, single-cpu
+    hostgroups: computers, lenny, hasbootfs, single-cpu, hassrvfs, postgres83-hosts, ftpd-hosts, rsyncd-hosts
   bellini:
     address: 137.82.84.79
     parents: gw-ubc
-    hostgroups: computers, lenny, hasbootfs, nfs-client, hassrvfs, aacraid
+    hostgroups: computers, lenny, hasbootfs, nfs-client, hassrvfs, aacraid, heavy-exim
+  morricone:
+    address: 137.82.84.81
+    parents: gw-ubc
+    hostgroups: computers, lenny, hasbootfs, hassrvfs, aacraid, postgres83-hosts, ftpd-hosts, rsyncd-hosts
   stabile:
     address: 137.82.84.72
     parents: gw-ubc
-    hostgroups: computers, lenny, hashomefs, sw-raid, rsyncd-hosts
+    hostgroups: computers, lenny, hashomefs, sw-raid, rsyncd-hosts, postgres84-hosts
   cimarosa:
     address: 137.82.84.80
     parents: gw-ubc
+    hostgroups: computers, lenny, hasbootfs, aacraid, hassrvfs, nfs-client
+  paganini:
+    address: 137.82.84.82
+    parents: gw-ubc
+    hostgroups: computers, lenny, hasbootfs, aacraid, hassrvfs
+  respighi:
+    address: 137.82.84.83
+    parents: gw-ubc
+    hostgroups: computers, lenny, hasbootfs, aacraid, hassrvfs
+  vivaldi:
+    address: 137.82.84.84
+    parents: gw-ubc
     hostgroups: computers, lenny, hasbootfs, aacraid, hassrvfs
   # MSA 2000 (2012i)
   giustini:
@@ -641,12 +682,6 @@ hostgroups:
     alias: hosts not running samhain properly
     private: 1
 
-  #syslog-ng-hosts:
-  #  alias: hosts running syslog-ng instead of sysklogd
-  #  private: 1
-  #rsyslog-hosts:
-  #  alias: hosts running rsyslogd instead of sysklogd
-  #  private: 1
   postfix-hosts:
     alias: hosts running postfix instead of exim
     private: 1
@@ -674,12 +709,15 @@ hostgroups:
   rsyncd-hosts:
     alias: hosts providing rsync services via xinetd
     private: 1
-  postgres81-hosts:
-    alias: hosts running postgres81
-    private: 1
+  #postgres81-hosts:
+  #  alias: hosts running postgres81
+  #  private: 1
   postgres83-hosts:
     alias: hosts running postgres83
     private: 1
+  postgres84-hosts:
+    alias: hosts running postgres84
+    private: 1
   mysql-hosts:
     alias: hosts running mysql
     private: 1
@@ -692,6 +730,9 @@ hostgroups:
   acpid-hosts:
     alias: hosts running acpid
     private: 1
+  uploadqueue:
+    alias: hosts that are an anonymous ftp uploadqueue
+    private: 1
 
   nfs-client:
     alias: hosts mounting filesystems using NFS
@@ -797,7 +838,7 @@ services:
   -
     name: disk usage on /
     servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 90 95 /"
+    nrpe: "/usr/lib/nagios/plugins/check_disk 93 96 /"
     hosts: ries, klecker
   -
     name: disk usage on /boot
@@ -813,7 +854,7 @@ services:
     name: disk usage on /org
     servicegroups: diskspace
     nrpe: "/usr/lib/nagios/plugins/check_disk 80 90 /org"
-    hosts: sperger, raff, lobos, villa, steffani, saens, pergolesi, verdi, spontini, ravel, mahler, schroeder, piatti, pescetti, widor, schein, lebrun
+    hosts: sperger, raff, lobos, villa, steffani, saens, pergolesi, spontini, ravel, mahler, schroeder, piatti, pescetti, widor, schein, lebrun
   -
     name: disk usage on /org
     servicegroups: diskspace
@@ -833,7 +874,7 @@ services:
     name: disk usage on /tmp
     servicegroups: diskspace
     nrpe: "/usr/lib/nagios/plugins/check_disk 60 80 /tmp"
-    hosts: raff, gluck, saens, puccini, merkel, tartini, powell, piatti, escher
+    hosts: raff, saens, puccini, merkel, tartini, powell, piatti, escher
   -
     name: disk usage on /usr
     servicegroups: diskspace
@@ -844,11 +885,6 @@ services:
     servicegroups: diskspace
     nrpe: "/usr/lib/nagios/plugins/check_disk 75 90 /home"
     hostgroups: hashomefs
-  -
-    name: disk usage on /home
-    servicegroups: diskspace
-    nrpe: "/usr/lib/nagios/plugins/check_disk 90 95 /home"
-    hosts: gluck
   -
     name: disk usage on /mnt/hdc
     servicegroups: diskspace
@@ -899,14 +935,14 @@ services:
     name: backup
     nrpe: "sudo /usr/lib/nagios/plugins/dsa-check-dabackup"
     hostgroups: computers
-    normal_check_interval: 180
+    normal_check_interval: 60
     max_check_attempts: 2
     retry_check_interval: 5
   -
     name: backup server config
     nrpe: "/usr/lib/nagios/plugins/dsa-check-dabackup-server"
     hosts: bartok
-    normal_check_interval: 180
+    normal_check_interval: 60
     max_check_attempts: 2
     retry_check_interval: 5
 
@@ -916,19 +952,13 @@ services:
     servicegroups: kernel
     nrpe: "/usr/lib/nagios/plugins/dsa-check-running-kernel"
     hostgroups: computers
-    normal_check_interval: 180
+    normal_check_interval: 60
     retry_check_interval: 5
 
  ####
-  -
-    name: process - puppet
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:8 -c 1: -u root -C ruby -a 'ruby /usr/sbin/puppetd -w 5 --factsync'"
-    hostgroups: lenny
-    excludehosts: agnesi
-
   -
     name: puppet
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-file_age -f /var/lib/puppet/state/state.yaml"
+    nrpe: "/usr/lib/nagios/plugins/dsa-check-file_age -i 540 -f /var/lib/puppet/state/state.yaml"
     hostgroups: lenny
     excludehosts: agnesi
 
@@ -1017,11 +1047,6 @@ services:
     check: dsa_check_ssh_port!2260
     hosts: agnesi
     normal_check_interval:  180
-  -
-    name: "network service - sshd - 443"
-    check: dsa_check_ssh_port!443
-    hosts: gluck
-    normal_check_interval:  180
 
   -
     name: "network service - sshd - version"
@@ -1110,21 +1135,8 @@ services:
     name: process - syslog-ng
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C syslog-ng  -a '/sbin/syslog-ng -p /var/run/syslog-ng.pid'"
     hostgroups: lenny
+    hosts: rietz
     excludehosts: agnesi
- ###
- # -
- #   name: process - rsyslogd
- #   nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C rsyslogd  -a '/usr/sbin/rsyslogd -c3'"
- #   hostgroups: rsyslog-hosts
- ###
-  -
-    name: process - syslogd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C syslogd  -a '/sbin/syslogd'"
-    hosts: rietz, verdi
-  -
-    name: process - klogd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C klogd  -a '/sbin/klogd -x'"
-    hosts: rietz, verdi
 
  ### MAIL STUFF
  ###
@@ -1133,17 +1145,17 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:10 -c 1: -u Debian-exim -C exim4 -a '/usr/sbin/exim4 -bd -q'"
     hostgroups: computers
     excludehostgroups: postfix-hosts
-    excludehosts: master, rietz, merkel, gluck
+    excludehosts: master, rietz, merkel
   -
     name: process - exim - total
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:50 -c 1: -C exim4"
     hostgroups: computers
     excludehostgroups: postfix-hosts
-    excludehosts: master, rietz, merkel, gluck
+    excludehosts: master, rietz, merkel
   -
     name: process - exim
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:300 -c 1:500 -C exim4 -a '/usr/sbin/exim4'"
-    hosts: master, rietz, merkel, gluck
+    hosts: master, rietz, merkel
  ###
   -
     name: process - clamav - clamd
@@ -1158,12 +1170,6 @@ services:
     name: process - clamav - freshclam
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u clamav -C freshclam -a '/usr/bin/freshclam -d --quiet'"
     hostgroups: heavy-exim, heavy-postfix
-  -
-    name: process - clamav - getsigs
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u clamav -C getclamsigs -a 'getclamsigs'"
-    hostgroups: heavy-exim, heavy-postfix
-    excludehosts: master, powell
-  #
   -
     name: unwanted process - clamav
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C clamd"
@@ -1174,18 +1180,11 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C freshclam"
     hostgroups: computers
     excludehostgroups: heavy-exim, heavy-postfix
-  -
-    name: unwanted process - clamav - getsigs
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C getclamsigs"
-    hostgroups: computers
-    excludehostgroups: heavy-exim, heavy-postfix
-    hosts: master, powell
- ###
   -
     name: process - spamd - master
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 5 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
     hostgroups: heavy-exim
-    excludehosts: rietz, merkel, raff, powell
+    excludehosts: rietz, merkel, raff, powell, bellini
   -
     name: process - spamd - master
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 20 --min-spare=5 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
@@ -1200,7 +1199,7 @@ services:
     hosts: liszt
     hostgroups: heavy-exim
     depends: process - spamd - master
-    excludehosts: rietz, merkel, raff
+    excludehosts: rietz, merkel, raff, bellini
   #
   -
     name: process - spamd - master
@@ -1220,7 +1219,7 @@ services:
   -
     name: unwanted process - spamd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C spamd"
-    hosts: merkel, raff
+    hosts: merkel, raff, bellini
 
  ###
   #-
@@ -1335,19 +1334,6 @@ services:
     hostgroups: postfix-hosts
     depends: process - postfix - master
 
-  -
-    name: process - postfix - smtpd
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:40 -c 0:90 -u postfix -C smtpd -a 'smtpd -n smtp -t inet -u -c'"
-    hostgroups: postfix-hosts
-    excludehosts: liszt
-    depends: process - postfix - master
-  -
-    name: process - postfix - smtp
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:10 -c 0:15 -u postfix -C smtp -a 'smtp -t unix -u -c'"
-    hostgroups: postfix-hosts
-    excludehosts: liszt
-    depends: process - postfix - master
-
   -
     name: process - postfix - smtpd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:150 -c 0:200 -u postfix -C smtpd -a 'smtpd -n smtp -t inet -u -c'"
@@ -1371,7 +1357,6 @@ services:
     name: network service - smtp
     check: dsa_check_smtp
     hostgroups: postfix-hosts
-    excludehosts: verdi
     depends: process - postfix - master
   -
     name: network service - submission
@@ -1383,11 +1368,6 @@ services:
     check: dsa_check_smtp_port!2025
     hostgroups: incomingmailrelayed2025
     depends: process - exim
-  -
-    name: network service - smtp - port 2025
-    check: dsa_check_smtp_port!2025
-    hosts: verdi
-    depends: process - postfix - master
   -
     name: network service local - smtps cert
     nrpe: "/usr/lib/nagios/plugins/check_http -H localhost -p 465 -S -C 14 -t 45"
@@ -1400,7 +1380,7 @@ services:
     name: setup - dsa config
     nrpe: "/usr/lib/nagios/plugins/dsa-check-config"
     hostgroups: computers
-    normal_check_interval: 120
+    normal_check_interval: 60
   -
     name: setup - ud-ldap freshness
     nrpe: "/usr/lib/nagios/plugins/dsa-check-udldap-freshness"
@@ -1449,11 +1429,17 @@ services:
     name: unwanted process - inetd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C inetd"
     hostgroups: computers
+    excludehosts: rietz
   -
     name: unwanted process - snmpd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C snmpd"
     hostgroups: computers
 
+ ####
+  -
+    name: "host SSL cert"
+    nrpe: "if [ -e /etc/ssl/certs/thishost.pem ]; then /usr/lib/nagios/plugins/dsa-check-cert-expire /etc/ssl/certs/thishost.pem; else echo 'No thishost.pem on this host.'; fi"
+    hostgroups: computers
 
  ############ Processes/Services that only run on some computers ############
  ####
@@ -1503,12 +1489,6 @@ services:
     servicegroups: raid
     nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-areca"
     hosts: powell
- ###
-  -
-    name: RAID - DAC960
-    servicegroups: raid
-    nrpe: "/usr/lib/nagios/plugins/dsa-check-raid-dac960"
-    hosts: verdi
  ###
   -
     name: RAID - aacraid
@@ -1568,13 +1548,13 @@ services:
   -
     name: process - xinetd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C xinetd -a '/usr/sbin/xinetd -pidfile /var/run/xinetd.pid -stayalive'"
-    hosts: gluck, zelenka, ancina, draghi
+    hosts: zelenka, ancina, draghi
     hostgroups: rsyncd-hosts
   -
     name: unwanted process - xinetd
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C xinetd"
     hostgroups: computers
-    excludehosts: gluck, zelenka, ancina, draghi
+    excludehosts: zelenka, ancina, draghi
     excludehostgroups: rsyncd-hosts
  ###
   -
@@ -1629,32 +1609,20 @@ services:
     name: network service - http
     check: check_http
     depends: kassia:process - apache2 - master
-    hosts: kassia-sec, kassia-ftp
-
-
-  # apache1 process on merkel
-  -
-    name: process - apache - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C apache -a /usr/sbin/apache"
-    hosts: merkel
-  -
-    name: process - apache - worker
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 2:75 -c 1:150 -u www-data -C apache -a /usr/sbin/apache"
-    hosts: merkel
-    depends: process - apache - master
+    hosts: kassia-sec, kassia-ftp, kassia-volatile
 
   # keyserver on raff
   -
     name: network service - http keyserver
     check: dsa_check_http_port!11371
-    hosts: raff
+    hosts: kaufmann
     depends: process - apache2 - master
 
   # https on various hosts
   -
     name: network service - https
     check: check_https
-    hosts: ries, klecker, draghi, liszt, spohr
+    hosts: ries, klecker, draghi, liszt, spohr, widor, rietz
     depends: "process - apache2 - master"
     normal_check_interval: 120
   -
@@ -1667,7 +1635,7 @@ services:
     # draghi           db.debian.org
     # merkel2          nm.debian.org
     # liszt            lists.debian.org
-    hosts: ries, klecker, spohr, spohr2, draghi, merkel2, liszt
+    hosts: ries, klecker, spohr, spohr2, draghi, merkel2, liszt, widor, rietz
     depends: network service - https
     normal_check_interval: 60
 
@@ -1715,17 +1683,17 @@ services:
   -
     name: process - vsftp - listener
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C vsftpd -a 'vsftpd: LISTENER'"
-    hostgroups: ftpd-hosts
+    hostgroups: ftpd-hosts, uploadqueue
     excludehosts: kassia
   -
     name: process - vsftp - instance
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:80 -c 0:100 -u ftp -C vsftpd -a 'vsftpd: '"
-    hostgroups: ftpd-hosts
+    hostgroups: ftpd-hosts, uploadqueue
     excludehosts: kassia
   -
     name: network service - ftp
     check: check_ftp
-    hostgroups: ftpd-hosts
+    hostgroups: ftpd-hosts, uploadqueue
     excludehosts: kassia
     depends: process - vsftp - listener
   -
@@ -1738,34 +1706,37 @@ services:
   -
     name: process - debianqueued
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u dak -C debianqueued"
-    hosts: ries, ravel, klecker
+    hostgroups: uploadqueue
 
  ###
-  -
-    name: process - postresql81 - master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postmaster -a '/usr/lib/postgresql/8.1/bin/postmaster -D /var/lib/postgresql/8.1/main -c config_file=/etc/postgresql/8.1/main/postgresql.conf'"
-    hostgroups: postgres81-hosts
-  -
-    name: process - postresql81 - writer
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postmaster -a 'postgres: writer process'"
-    hostgroups: postgres81-hosts
-    depends: process - postresql81 - master
-  -
-    name: process - postresql81 - buffer
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postmaster -a 'postgres: stats buffer process'"
-    hostgroups: postgres81-hosts
-    depends: process - postresql81 - master
-  -
-    name: process - postresql81 - collector
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postmaster -a 'postgres: stats collector process'"
-    hostgroups: postgres81-hosts
-    depends: process - postresql81 - master
+  #-
+  #  name: process - postresql81 - master
+  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postmaster -a '/usr/lib/postgresql/8.1/bin/postmaster -D /var/lib/postgresql/8.1/main -c config_file=/etc/postgresql/8.1/main/postgresql.conf'"
+  #  hostgroups: postgres81-hosts
+  #-
+  #  name: process - postresql81 - writer
+  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postmaster -a 'postgres: writer process'"
+  #  hostgroups: postgres81-hosts
+  #  depends: process - postresql81 - master
+  #-
+  #  name: process - postresql81 - buffer
+  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postmaster -a 'postgres: stats buffer process'"
+  #  hostgroups: postgres81-hosts
+  #  depends: process - postresql81 - master
+  #-
+  #  name: process - postresql81 - collector
+  #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postmaster -a 'postgres: stats collector process'"
+  #  hostgroups: postgres81-hosts
+  #  depends: process - postresql81 - master
  ####
+  -
+    name: process - postresql84 - master
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.4/bin/postgres'"
+    hostgroups: postgres84-hosts
   -
     name: process - postresql83 - master
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.3/bin/postgres -D /var/lib/postgresql/8.3/main -c config_file=/etc/postgresql/8.3/main/postgresql.conf'"
     hostgroups: postgres83-hosts
-    excludehosts: klecker
   #-
   #  name: process - postresql83 - master udd
   #  nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.3/bin/postgres -D /var/lib/postgresql/8.3/udd -c config_file=/etc/postgresql/8.3/udd/postgresql.conf'"
@@ -1773,10 +1744,14 @@ services:
   -
     name: process - postresql83 - dak master
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.3/bin/postgres -D /var/lib/postgresql/8.3/dak -c config_file=/etc/postgresql/8.3/dak/postgresql.conf'"
-    hosts: ries, klecker
+    hosts: klecker, chopin
   -
-    name: process - postresql83 - dak-dev master
-    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.3/bin/postgres -D /var/lib/postgresql/8.3/dak-dev -c config_file=/etc/postgresql/8.3/dak-dev/postgresql.conf'"
+    name: process - postresql84 - dak master
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.4/bin/postgres -D /var/lib/postgresql/8.4/dak -c config_file=/etc/postgresql/8.4/dak/postgresql.conf'"
+    hosts: ries
+  -
+    name: process - postresql84 - dak-dev master
+    nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.4/bin/postgres -D /var/lib/postgresql/8.4/dak-dev -c config_file=/etc/postgresql/8.4/dak-dev/postgresql.conf'"
     hosts: ries
  ####
   -
@@ -1799,6 +1774,11 @@ services:
     nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u stunnel4 -C stunnel4 -a '/usr/bin/stunnel4 /etc/stunnel/postgres-udd.conf'"
     hosts: merkel, master
 
+  -
+    name: udd stunnel - master cert
+    nrpe: "/usr/lib/nagios/plugins/check_http -H localhost -p 8080 -S -C 14 -t 45"
+    hosts: samosa
+
  ####
   #-
   #  name: process - xenconsoled
@@ -1867,10 +1847,6 @@ services:
     hostgroups: nfs-server
  # see if the nfs stuff works and doesn't hang.
   # the df check all script will also hang, but we don't appear to pay attention to that
-  -
-    name: nfs mount ftp archive
-    nrpe: "/usr/lib/nagios/plugins/check_disk 100 100 /home/org/ftp.root/debian"
-    hosts: gluck
   -
     name: nfs mount ftp archive
     nrpe: "/usr/lib/nagios/plugins/check_disk 100 100 /org/mirrors/ftp.debian.org/ftp"
@@ -1888,16 +1864,15 @@ services:
     hosts: global
   -
     name: mirror sync - security
-    check: "dsa_check_mirrorsync!security.debian.org!project/trace/security-master.debian.org"
+    check: "dsa_check_mirrorsync!security-nagios.debian.org!project/trace/security-master.debian.org"
     hosts: global
   -
-    name: mirror sync - security.eu
-    check: "dsa_check_mirrorsync!security.eu.debian.org!project/trace/security-master.debian.org"
-    hosts: global
-  -
-    name: mirror sync - security.us
-    check: "dsa_check_mirrorsync!security.us.debian.org!project/trace/security-master.debian.org"
+    name: mirror sync - packages
+    check: "dsa_check_mirrorsync!packages.debian.org!Pics/.trace"
     hosts: global
+    normal_check_interval: 15
+    max_check_attempts: 5
+    retry_check_interval: 5
   -
     name: DNS SOA sync - security.geo.debian.org
     check: "dsa_check_soas!security.geo.debian.org"
@@ -1926,6 +1901,22 @@ services:
     name: DNS SOA sync - alioth.debian.org
     check: "dsa_check_soas_add!alioth.debian.org!alioth.debian.org"
     hosts: global
+  -
+    name: DNS SOA sync - 2.5.1.1.8.0.0.8.d.8.0.1.0.0.2.ip6.arpa
+    check: "dsa_check_soas!2.5.1.1.8.0.0.8.d.8.0.1.0.0.2.ip6.arpa"
+    hosts: global
+  -
+    name: DNS SOA sync - a.5.1.1.8.0.0.8.d.8.0.1.0.0.2.ip6.arpa
+    check: "dsa_check_soas!a.5.1.1.8.0.0.8.d.8.0.1.0.0.2.ip6.arpa"
+    hosts: global
+  -
+    name: DNS SOA sync - 2.1.0.0.0.0.0.2.8.8.8.0.1.0.0.2.ip6.arpa
+    check: "dsa_check_soas!2.1.0.0.0.0.0.2.8.8.8.0.1.0.0.2.ip6.arpa"
+    hosts: global
+  -
+    name: DNS SOA sync - 2.6.a.0.4.6.5.6.1.0.0.0.2.0.0.0.8.d.8.0.1.0.0.2.ip6.arpa
+    check: "dsa_check_soas!2.6.a.0.4.6.5.6.1.0.0.0.2.0.0.0.8.d.8.0.1.0.0.2.ip6.arpa"
+    hosts: global
  ############
   -
     name: ping alive check