parents: gw-HP-ftc
hostgroups: routing-infrastructure
contacts: tjrc1
- gw-lrz:
- address: 129.187.0.150
- parents: gw-HP-ftc
- hostgroups: routing-infrastructure
gw-frost:
address: 130.81.242.195
parents: gw-HP-ftc
# parents: gw-HP-ftc
# hostgroups: routing-infrastructure
gw-agnesi:
- address: 65.173.90.18
+ address: 65.173.90.22
parents: gw-HP-ftc
hostgroups: routing-infrastructure
gw-ubc:
parents: gw-HP-ftc
hostgroups: routing-infrastructure
contacts: lfilipoz
+ gw-ubcnew:
+ address: 206.12.19.254
+ parents: gw-HP-ftc
+ hostgroups: routing-infrastructure
+ contacts: lfilipoz
gw-carnet:
address: 161.53.160.1
parents: gw-HP-ftc
parents: gw-HP-ftc
hostgroups: routing-infrastructure
gw-esiee:
- address: 147.215.2.249
+ address: 195.220.83.13
parents: gw-HP-ftc
hostgroups: routing-infrastructure
gw-ghent:
samosa:
address: 192.25.206.57
parents: spohr
- hostgroups: computers, service, dl380, lenny, hassrvfs, hasbootfs, acpid-hosts, ulogd-hosts
+ hostgroups: computers, service, dl380, lenny, hassrvfs, hasbootfs, acpid-hosts, ulogd-hosts, nfs-client, postgres84-hosts
raff:
address: 192.25.206.59
parents: spohr
peri:
address: 192.25.206.15
parents: spohr
- hostgroups: computers, buildd, sw-raid, hasbootfs, lenny
+ hostgroups: computers, buildd, sw-raid, hasbootfs, lenny, single-cpu
contacts: dannf
penalosa:
address: 192.25.206.68
parents: spohr
- hostgroups: computers, buildd, sw-raid, hasbootfs, lenny
+ hostgroups: computers, buildd, hasbootfs, lenny
contacts: dannf
mundy:
address: 192.25.206.62
byrd:
address: 82.195.75.101
parents: unger
- hostgroups: computers, service, lenny, hasbootfs, hassrvfs
+ hostgroups: computers, service, lenny, hasbootfs, hassrvfs, postgres84-hosts
master:
address: 70.103.162.29
parents: gw-brainfood
hostgroups: computers, general, dl380, acpid-hosts, lenny, buildd, hasbootfs, hassrvfs
+
ries:
address: 128.148.34.103
parents: gw-brown.edu
- hostgroups: computers, service, apache2-hosts, bind9-hosts, ftpd-hosts, dl385, rsyncd-hosts, postgres83-hosts, heavy-exim, acpid-hosts, lenny
+ hostgroups: computers, service, apache2-hosts, bind9-hosts, ftpd-hosts, dl385, rsyncd-hosts, postgres83-hosts, heavy-exim, acpid-hosts, lenny, uploadqueue
mayer:
address: 140.211.166.78
address: 140.211.166.44
parents: rietz
hostgroups: secondary-IPs
+ zee:
+ address: 140.211.166.16
+ parents: gw-osuosl
+ hostgroups: computers, porterbox, lenny, hassrvfs, hasbootfs
villa:
address: 212.211.132.32
klecker:
address: 194.109.137.218
parents: gw-xs4all
- hostgroups: computers, service, apache2-hosts, ftpd-hosts, rsyncd-hosts, bind9-hosts, dl385, postgres83-hosts, heavy-exim, lenny
+ hostgroups: computers, service, apache2-hosts, ftpd-hosts, rsyncd-hosts, bind9-hosts, dl385, heavy-exim, lenny
saens:
address: 128.101.240.212
chopin:
address: 195.20.242.124
parents: schumann
- hostgroups: computers, ulogd-hosts, lenny, hassrvfs
+ hostgroups: computers, service, apache2-hosts, ulogd-hosts, lenny, hassrvfs, hasbootfs, rsyncd-hosts, uploadqueue
geo3:
address: 195.20.242.125
parents: schumann
hostgroups: computers, service, lenny, hasbootfs, single-cpu, bind9-hosts
+ soler:
+ address: 195.20.242.126
+ parents: schumann
+ hostgroups: computers, service, lenny, hasbootfs, hassrvfs
caballero:
address: 193.201.200.200
address: 130.89.149.226
parents: kassia
hostgroups: secondary-IPs
- kassia4:
+ kassia-volatile:
address: 130.89.149.227
parents: kassia
hostgroups: secondary-IPs
contacts: luk
agnesi:
- address: 65.173.90.83
+ address: 67.233.102.241
parents: gw-agnesi
hostgroups: deadslow, lenny
hostgroups: computers, buildd, hasbootfs, lenny
contacts: lfilipoz
ravel:
- address: 137.82.84.66
- parents: gw-ubc
- hostgroups: computers, general, dl385, apache2-hosts, acpid-hosts, ftpd-hosts, hasbootfs, lenny, nfs-server, rsyncd-hosts
+ address: 206.12.19.5
+ parents: gw-ubcnew
+ hostgroups: computers, general, dl385, apache2-hosts, acpid-hosts, ftpd-hosts, hasbootfs, lenny, nfs-server, rsyncd-hosts, bind9-hosts, uploadqueue
dijkstra:
address: 137.82.84.70
parents: gw-ubc
- hostgroups: computers, bl460, acpid-hosts, lenny
+ hostgroups: computers, bl460, acpid-hosts, lenny, ulogd-hosts
+ luchesi:
+ address: 206.12.19.214
+ parents: gw-ubcnew
+ hostgroups: computers, bl460, acpid-hosts, lenny, ulogd-hosts
+ wolkenstein:
+ address: 137.82.84.89
+ parents: dijkstra
+ hostgroups: computers, lenny, hasbootfs, hassrvfs
brahms:
address: 137.82.84.74
parents: dijkstra
bellini:
address: 137.82.84.79
parents: gw-ubc
- hostgroups: computers, lenny, hasbootfs, nfs-client, hassrvfs, aacraid
+ hostgroups: computers, lenny, hasbootfs, nfs-client, hassrvfs, aacraid, heavy-exim
+ morricone:
+ address: 137.82.84.81
+ parents: gw-ubc
+ hostgroups: computers, lenny, hasbootfs, hassrvfs, aacraid, postgres83-hosts, ftpd-hosts, rsyncd-hosts
stabile:
address: 137.82.84.72
parents: gw-ubc
- hostgroups: computers, lenny, hashomefs, sw-raid, rsyncd-hosts
+ hostgroups: computers, lenny, hashomefs, sw-raid, rsyncd-hosts, postgres84-hosts
cimarosa:
address: 137.82.84.80
parents: gw-ubc
+ hostgroups: computers, lenny, hasbootfs, aacraid, hassrvfs, nfs-client
+ paganini:
+ address: 137.82.84.82
+ parents: gw-ubc
+ hostgroups: computers, lenny, hasbootfs, aacraid, hassrvfs
+ respighi:
+ address: 137.82.84.83
+ parents: gw-ubc
+ hostgroups: computers, lenny, hasbootfs, aacraid, hassrvfs
+ vivaldi:
+ address: 137.82.84.84
+ parents: gw-ubc
hostgroups: computers, lenny, hasbootfs, aacraid, hassrvfs
# MSA 2000 (2012i)
giustini:
alias: hosts not running samhain properly
private: 1
- #syslog-ng-hosts:
- # alias: hosts running syslog-ng instead of sysklogd
- # private: 1
- #rsyslog-hosts:
- # alias: hosts running rsyslogd instead of sysklogd
- # private: 1
postfix-hosts:
alias: hosts running postfix instead of exim
private: 1
postgres83-hosts:
alias: hosts running postgres83
private: 1
+ postgres84-hosts:
+ alias: hosts running postgres84
+ private: 1
mysql-hosts:
alias: hosts running mysql
private: 1
acpid-hosts:
alias: hosts running acpid
private: 1
+ uploadqueue:
+ alias: hosts that are an anonymous ftp uploadqueue
+ private: 1
nfs-client:
alias: hosts mounting filesystems using NFS
-
name: disk usage on /
servicegroups: diskspace
- nrpe: "/usr/lib/nagios/plugins/check_disk 90 95 /"
+ nrpe: "/usr/lib/nagios/plugins/check_disk 93 96 /"
hosts: ries, klecker
-
name: disk usage on /boot
name: backup
nrpe: "sudo /usr/lib/nagios/plugins/dsa-check-dabackup"
hostgroups: computers
- normal_check_interval: 180
+ normal_check_interval: 60
max_check_attempts: 2
retry_check_interval: 5
-
name: backup server config
nrpe: "/usr/lib/nagios/plugins/dsa-check-dabackup-server"
hosts: bartok
- normal_check_interval: 180
+ normal_check_interval: 60
max_check_attempts: 2
retry_check_interval: 5
servicegroups: kernel
nrpe: "/usr/lib/nagios/plugins/dsa-check-running-kernel"
hostgroups: computers
- normal_check_interval: 180
+ normal_check_interval: 60
retry_check_interval: 5
####
-
name: puppet
- nrpe: "/usr/lib/nagios/plugins/dsa-check-file_age -i 300 -f /var/lib/puppet/state/state.yaml"
+ nrpe: "/usr/lib/nagios/plugins/dsa-check-file_age -i 540 -f /var/lib/puppet/state/state.yaml"
hostgroups: lenny
excludehosts: agnesi
name: process - syslog-ng
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C syslog-ng -a '/sbin/syslog-ng -p /var/run/syslog-ng.pid'"
hostgroups: lenny
- excludehosts: agnesi
- ###
- # -
- # name: process - rsyslogd
- # nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C rsyslogd -a '/usr/sbin/rsyslogd -c3'"
- # hostgroups: rsyslog-hosts
- ###
- -
- name: process - syslogd
- nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C syslogd -a '/sbin/syslogd'"
- hosts: rietz
- -
- name: process - klogd
- nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C klogd -a '/sbin/klogd -x'"
hosts: rietz
+ excludehosts: agnesi
### MAIL STUFF
###
name: process - spamd - master
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 5 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
hostgroups: heavy-exim
- excludehosts: rietz, merkel, raff, powell
+ excludehosts: rietz, merkel, raff, powell, bellini
-
name: process - spamd - master
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 20 --min-spare=5 --helper-home-dir -d --pidfile=/var/run/spamd.pid'"
hosts: liszt
hostgroups: heavy-exim
depends: process - spamd - master
- excludehosts: rietz, merkel, raff
+ excludehosts: rietz, merkel, raff, bellini
#
-
name: process - spamd - master
-
name: unwanted process - spamd
nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C spamd"
- hosts: merkel, raff
+ hosts: merkel, raff, bellini
###
#-
name: setup - dsa config
nrpe: "/usr/lib/nagios/plugins/dsa-check-config"
hostgroups: computers
- normal_check_interval: 120
+ normal_check_interval: 60
-
name: setup - ud-ldap freshness
nrpe: "/usr/lib/nagios/plugins/dsa-check-udldap-freshness"
name: unwanted process - inetd
nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C inetd"
hostgroups: computers
+ excludehosts: rietz
-
name: unwanted process - snmpd
nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C snmpd"
hostgroups: computers
+ ####
+ -
+ name: "host SSL cert"
+ nrpe: "if [ -e /etc/ssl/certs/thishost.pem ]; then /usr/lib/nagios/plugins/dsa-check-cert-expire /etc/ssl/certs/thishost.pem; else echo 'No thishost.pem on this host.'; fi"
+ hostgroups: computers
############ Processes/Services that only run on some computers ############
####
name: network service - http
check: check_http
depends: kassia:process - apache2 - master
- hosts: kassia-sec, kassia-ftp
-
-
- # apache1 process on merkel
- -
- name: process - apache - master
- nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C apache -a /usr/sbin/apache"
- hosts: merkel
- -
- name: process - apache - worker
- nrpe: "/usr/lib/nagios/plugins/check_procs -w 2:75 -c 1:150 -u www-data -C apache -a /usr/sbin/apache"
- hosts: merkel
- depends: process - apache - master
+ hosts: kassia-sec, kassia-ftp, kassia-volatile
# keyserver on raff
-
name: network service - http keyserver
check: dsa_check_http_port!11371
- hosts: raff
+ hosts: kaufmann
depends: process - apache2 - master
# https on various hosts
-
name: network service - https
check: check_https
- hosts: ries, klecker, draghi, liszt, spohr
+ hosts: ries, klecker, draghi, liszt, spohr, widor, rietz
depends: "process - apache2 - master"
normal_check_interval: 120
-
# draghi db.debian.org
# merkel2 nm.debian.org
# liszt lists.debian.org
- hosts: ries, klecker, spohr, spohr2, draghi, merkel2, liszt
+ hosts: ries, klecker, spohr, spohr2, draghi, merkel2, liszt, widor, rietz
depends: network service - https
normal_check_interval: 60
-
name: process - vsftp - listener
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C vsftpd -a 'vsftpd: LISTENER'"
- hostgroups: ftpd-hosts
+ hostgroups: ftpd-hosts, uploadqueue
excludehosts: kassia
-
name: process - vsftp - instance
nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:80 -c 0:100 -u ftp -C vsftpd -a 'vsftpd: '"
- hostgroups: ftpd-hosts
+ hostgroups: ftpd-hosts, uploadqueue
excludehosts: kassia
-
name: network service - ftp
check: check_ftp
- hostgroups: ftpd-hosts
+ hostgroups: ftpd-hosts, uploadqueue
excludehosts: kassia
depends: process - vsftp - listener
-
-
name: process - debianqueued
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u dak -C debianqueued"
- hosts: ries, ravel, klecker
+ hostgroups: uploadqueue
###
#-
# hostgroups: postgres81-hosts
# depends: process - postresql81 - master
####
+ -
+ name: process - postresql84 - master
+ nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.4/bin/postgres'"
+ hostgroups: postgres84-hosts
-
name: process - postresql83 - master
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.3/bin/postgres -D /var/lib/postgresql/8.3/main -c config_file=/etc/postgresql/8.3/main/postgresql.conf'"
hostgroups: postgres83-hosts
- excludehosts: klecker
#-
# name: process - postresql83 - master udd
# nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.3/bin/postgres -D /var/lib/postgresql/8.3/udd -c config_file=/etc/postgresql/8.3/udd/postgresql.conf'"
-
name: process - postresql83 - dak master
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.3/bin/postgres -D /var/lib/postgresql/8.3/dak -c config_file=/etc/postgresql/8.3/dak/postgresql.conf'"
- hosts: ries, klecker
+ hosts: klecker, chopin
-
- name: process - postresql83 - dak-dev master
- nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.3/bin/postgres -D /var/lib/postgresql/8.3/dak-dev -c config_file=/etc/postgresql/8.3/dak-dev/postgresql.conf'"
+ name: process - postresql84 - dak master
+ nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.4/bin/postgres -D /var/lib/postgresql/8.4/dak -c config_file=/etc/postgresql/8.4/dak/postgresql.conf'"
+ hosts: ries
+ -
+ name: process - postresql84 - dak-dev master
+ nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.4/bin/postgres -D /var/lib/postgresql/8.4/dak-dev -c config_file=/etc/postgresql/8.4/dak-dev/postgresql.conf'"
hosts: ries
####
-
nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u stunnel4 -C stunnel4 -a '/usr/bin/stunnel4 /etc/stunnel/postgres-udd.conf'"
hosts: merkel, master
+ -
+ name: udd stunnel - master cert
+ nrpe: "/usr/lib/nagios/plugins/check_http -H localhost -p 8080 -S -C 14 -t 45"
+ hosts: samosa
+
####
#-
# name: process - xenconsoled
hosts: global
-
name: mirror sync - security
- check: "dsa_check_mirrorsync!security.debian.org!project/trace/security-master.debian.org"
- hosts: global
- -
- name: mirror sync - security.eu
- check: "dsa_check_mirrorsync!security.eu.debian.org!project/trace/security-master.debian.org"
- hosts: global
- -
- name: mirror sync - security.us
- check: "dsa_check_mirrorsync!security.us.debian.org!project/trace/security-master.debian.org"
+ check: "dsa_check_mirrorsync!security-nagios.debian.org!project/trace/security-master.debian.org"
hosts: global
-
name: mirror sync - packages
name: DNS SOA sync - alioth.debian.org
check: "dsa_check_soas_add!alioth.debian.org!alioth.debian.org"
hosts: global
+ -
+ name: DNS SOA sync - 2.5.1.1.8.0.0.8.d.8.0.1.0.0.2.ip6.arpa
+ check: "dsa_check_soas!2.5.1.1.8.0.0.8.d.8.0.1.0.0.2.ip6.arpa"
+ hosts: global
+ -
+ name: DNS SOA sync - a.5.1.1.8.0.0.8.d.8.0.1.0.0.2.ip6.arpa
+ check: "dsa_check_soas!a.5.1.1.8.0.0.8.d.8.0.1.0.0.2.ip6.arpa"
+ hosts: global
+ -
+ name: DNS SOA sync - 2.1.0.0.0.0.0.2.8.8.8.0.1.0.0.2.ip6.arpa
+ check: "dsa_check_soas!2.1.0.0.0.0.0.2.8.8.8.0.1.0.0.2.ip6.arpa"
+ hosts: global
+ -
+ name: DNS SOA sync - 2.6.a.0.4.6.5.6.1.0.0.0.2.0.0.0.8.d.8.0.1.0.0.2.ip6.arpa
+ check: "dsa_check_soas!2.6.a.0.4.6.5.6.1.0.0.0.2.0.0.0.8.d.8.0.1.0.0.2.ip6.arpa"
+ hosts: global
############
-
name: ping alive check