X-Git-Url: https://git.adam-barratt.org.uk/?a=blobdiff_plain;f=config%2Fnagios-master.cfg;h=eef3446c93ed4aa4a4d56162c318f5e15851245a;hb=bf62c544c7f302196d043d0119719778feebc58b;hp=a74e0230337a570ef580b19c8c467b1905c4102c;hpb=09507a70ceb68af2721fd1bfa8f536bf860054a0;p=mirror%2Fdsa-nagios.git diff --git a/config/nagios-master.cfg b/config/nagios-master.cfg index a74e023..eef3446 100644 --- a/config/nagios-master.cfg +++ b/config/nagios-master.cfg @@ -81,10 +81,6 @@ servers: parents: gw-HP-ftc hostgroups: routing-infrastructure contacts: tjrc1 - gw-lrz: - address: 129.187.0.150 - parents: gw-HP-ftc - hostgroups: routing-infrastructure gw-frost: address: 130.81.242.195 parents: gw-HP-ftc @@ -115,7 +111,7 @@ servers: # parents: gw-HP-ftc # hostgroups: routing-infrastructure gw-agnesi: - address: 65.173.90.18 + address: 65.173.90.22 parents: gw-HP-ftc hostgroups: routing-infrastructure gw-ubc: @@ -123,6 +119,11 @@ servers: parents: gw-HP-ftc hostgroups: routing-infrastructure contacts: lfilipoz + gw-ubcnew: + address: 206.12.19.254 + parents: gw-HP-ftc + hostgroups: routing-infrastructure + contacts: lfilipoz gw-carnet: address: 161.53.160.1 parents: gw-HP-ftc @@ -157,7 +158,7 @@ servers: parents: gw-HP-ftc hostgroups: routing-infrastructure gw-esiee: - address: 147.215.2.249 + address: 195.220.83.13 parents: gw-HP-ftc hostgroups: routing-infrastructure gw-ghent: @@ -177,7 +178,7 @@ servers: samosa: address: 192.25.206.57 parents: spohr - hostgroups: computers, service, dl380, lenny, hassrvfs, hasbootfs, acpid-hosts, ulogd-hosts, nfs-client + hostgroups: computers, service, dl380, lenny, hassrvfs, hasbootfs, acpid-hosts, ulogd-hosts, nfs-client, postgres84-hosts raff: address: 192.25.206.59 parents: spohr @@ -200,12 +201,12 @@ servers: peri: address: 192.25.206.15 parents: spohr - hostgroups: computers, buildd, sw-raid, hasbootfs, lenny + hostgroups: computers, buildd, sw-raid, hasbootfs, lenny, single-cpu contacts: dannf penalosa: address: 192.25.206.68 parents: spohr - hostgroups: computers, buildd, sw-raid, hasbootfs, lenny + hostgroups: computers, buildd, hasbootfs, lenny contacts: dannf mundy: address: 192.25.206.62 @@ -278,7 +279,7 @@ servers: byrd: address: 82.195.75.101 parents: unger - hostgroups: computers, service, lenny, hasbootfs, hassrvfs + hostgroups: computers, service, lenny, hasbootfs, hassrvfs, postgres84-hosts master: address: 70.103.162.29 @@ -289,6 +290,7 @@ servers: parents: gw-brainfood hostgroups: computers, general, dl380, acpid-hosts, lenny, buildd, hasbootfs, hassrvfs + ries: address: 128.148.34.103 parents: gw-brown.edu @@ -314,6 +316,10 @@ servers: address: 140.211.166.44 parents: rietz hostgroups: secondary-IPs + zee: + address: 140.211.166.16 + parents: gw-osuosl + hostgroups: computers, porterbox, lenny, hassrvfs, hasbootfs villa: address: 212.211.132.32 @@ -352,7 +358,7 @@ servers: klecker: address: 194.109.137.218 parents: gw-xs4all - hostgroups: computers, service, apache2-hosts, ftpd-hosts, rsyncd-hosts, bind9-hosts, dl385, postgres83-hosts, heavy-exim, lenny + hostgroups: computers, service, apache2-hosts, ftpd-hosts, rsyncd-hosts, bind9-hosts, dl385, heavy-exim, lenny saens: address: 128.101.240.212 @@ -422,11 +428,15 @@ servers: chopin: address: 195.20.242.124 parents: schumann - hostgroups: computers, ulogd-hosts, lenny, hassrvfs + hostgroups: computers, service, apache2-hosts, ulogd-hosts, lenny, hassrvfs, hasbootfs, rsyncd-hosts geo3: address: 195.20.242.125 parents: schumann hostgroups: computers, service, lenny, hasbootfs, single-cpu, bind9-hosts + soler: + address: 195.20.242.126 + parents: schumann + hostgroups: computers, service, lenny, hasbootfs, hassrvfs caballero: address: 193.201.200.200 @@ -450,7 +460,7 @@ servers: address: 130.89.149.226 parents: kassia hostgroups: secondary-IPs - kassia4: + kassia-volatile: address: 130.89.149.227 parents: kassia hostgroups: secondary-IPs @@ -462,7 +472,7 @@ servers: contacts: luk agnesi: - address: 65.173.90.83 + address: 67.233.102.241 parents: gw-agnesi hostgroups: deadslow, lenny @@ -472,13 +482,17 @@ servers: hostgroups: computers, buildd, hasbootfs, lenny contacts: lfilipoz ravel: - address: 137.82.84.66 - parents: gw-ubc - hostgroups: computers, general, dl385, apache2-hosts, acpid-hosts, ftpd-hosts, hasbootfs, lenny, nfs-server, rsyncd-hosts + address: 206.12.19.5 + parents: gw-ubcnew + hostgroups: computers, general, dl385, apache2-hosts, acpid-hosts, ftpd-hosts, hasbootfs, lenny, nfs-server, rsyncd-hosts, bind9-hosts dijkstra: address: 137.82.84.70 parents: gw-ubc - hostgroups: computers, bl460, acpid-hosts, lenny + hostgroups: computers, bl460, acpid-hosts, lenny, ulogd-hosts + luchesi: + address: 206.12.19.214 + parents: gw-ubcnew + hostgroups: computers, bl460, acpid-hosts, lenny, ulogd-hosts wolkenstein: address: 137.82.84.89 parents: dijkstra @@ -502,7 +516,7 @@ servers: bellini: address: 137.82.84.79 parents: gw-ubc - hostgroups: computers, lenny, hasbootfs, nfs-client, hassrvfs, aacraid + hostgroups: computers, lenny, hasbootfs, nfs-client, hassrvfs, aacraid, heavy-exim morricone: address: 137.82.84.81 parents: gw-ubc @@ -510,10 +524,22 @@ servers: stabile: address: 137.82.84.72 parents: gw-ubc - hostgroups: computers, lenny, hashomefs, sw-raid, rsyncd-hosts + hostgroups: computers, lenny, hashomefs, sw-raid, rsyncd-hosts, postgres84-hosts cimarosa: address: 137.82.84.80 parents: gw-ubc + hostgroups: computers, lenny, hasbootfs, aacraid, hassrvfs, nfs-client + paganini: + address: 137.82.84.82 + parents: gw-ubc + hostgroups: computers, lenny, hasbootfs, aacraid, hassrvfs + respighi: + address: 137.82.84.83 + parents: gw-ubc + hostgroups: computers, lenny, hasbootfs, aacraid, hassrvfs + vivaldi: + address: 137.82.84.84 + parents: gw-ubc hostgroups: computers, lenny, hasbootfs, aacraid, hassrvfs # MSA 2000 (2012i) giustini: @@ -656,12 +682,6 @@ hostgroups: alias: hosts not running samhain properly private: 1 - #syslog-ng-hosts: - # alias: hosts running syslog-ng instead of sysklogd - # private: 1 - #rsyslog-hosts: - # alias: hosts running rsyslogd instead of sysklogd - # private: 1 postfix-hosts: alias: hosts running postfix instead of exim private: 1 @@ -695,6 +715,9 @@ hostgroups: postgres83-hosts: alias: hosts running postgres83 private: 1 + postgres84-hosts: + alias: hosts running postgres84 + private: 1 mysql-hosts: alias: hosts running mysql private: 1 @@ -812,7 +835,7 @@ services: - name: disk usage on / servicegroups: diskspace - nrpe: "/usr/lib/nagios/plugins/check_disk 90 95 /" + nrpe: "/usr/lib/nagios/plugins/check_disk 93 96 /" hosts: ries, klecker - name: disk usage on /boot @@ -909,14 +932,14 @@ services: name: backup nrpe: "sudo /usr/lib/nagios/plugins/dsa-check-dabackup" hostgroups: computers - normal_check_interval: 180 + normal_check_interval: 60 max_check_attempts: 2 retry_check_interval: 5 - name: backup server config nrpe: "/usr/lib/nagios/plugins/dsa-check-dabackup-server" hosts: bartok - normal_check_interval: 180 + normal_check_interval: 60 max_check_attempts: 2 retry_check_interval: 5 @@ -926,7 +949,7 @@ services: servicegroups: kernel nrpe: "/usr/lib/nagios/plugins/dsa-check-running-kernel" hostgroups: computers - normal_check_interval: 180 + normal_check_interval: 60 retry_check_interval: 5 #### @@ -1109,21 +1132,8 @@ services: name: process - syslog-ng nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C syslog-ng -a '/sbin/syslog-ng -p /var/run/syslog-ng.pid'" hostgroups: lenny - excludehosts: agnesi - ### - # - - # name: process - rsyslogd - # nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C rsyslogd -a '/usr/sbin/rsyslogd -c3'" - # hostgroups: rsyslog-hosts - ### - - - name: process - syslogd - nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C syslogd -a '/sbin/syslogd'" - hosts: rietz - - - name: process - klogd - nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C klogd -a '/sbin/klogd -x'" hosts: rietz + excludehosts: agnesi ### MAIL STUFF ### @@ -1171,7 +1181,7 @@ services: name: process - spamd - master nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 5 --helper-home-dir -d --pidfile=/var/run/spamd.pid'" hostgroups: heavy-exim - excludehosts: rietz, merkel, raff, powell + excludehosts: rietz, merkel, raff, powell, bellini - name: process - spamd - master nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u root -C spamd -a '/usr/sbin/spamd --create-prefs --max-children 20 --min-spare=5 --helper-home-dir -d --pidfile=/var/run/spamd.pid'" @@ -1186,7 +1196,7 @@ services: hosts: liszt hostgroups: heavy-exim depends: process - spamd - master - excludehosts: rietz, merkel, raff + excludehosts: rietz, merkel, raff, bellini # - name: process - spamd - master @@ -1206,7 +1216,7 @@ services: - name: unwanted process - spamd nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C spamd" - hosts: merkel, raff + hosts: merkel, raff, bellini ### #- @@ -1367,7 +1377,7 @@ services: name: setup - dsa config nrpe: "/usr/lib/nagios/plugins/dsa-check-config" hostgroups: computers - normal_check_interval: 120 + normal_check_interval: 60 - name: setup - ud-ldap freshness nrpe: "/usr/lib/nagios/plugins/dsa-check-udldap-freshness" @@ -1416,11 +1426,17 @@ services: name: unwanted process - inetd nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C inetd" hostgroups: computers + excludehosts: rietz - name: unwanted process - snmpd nrpe: "/usr/lib/nagios/plugins/check_procs -w 0:0 -C snmpd" hostgroups: computers + #### + - + name: "host SSL cert" + nrpe: "if [ -e /etc/ssl/certs/thishost.pem ]; then /usr/lib/nagios/plugins/dsa-check-cert-expire /etc/ssl/certs/thishost.pem; else echo 'No thishost.pem on this host.'; fi" + hostgroups: computers ############ Processes/Services that only run on some computers ############ #### @@ -1590,32 +1606,20 @@ services: name: network service - http check: check_http depends: kassia:process - apache2 - master - hosts: kassia-sec, kassia-ftp - - - # apache1 process on merkel - - - name: process - apache - master - nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1:1 -u root -C apache -a /usr/sbin/apache" - hosts: merkel - - - name: process - apache - worker - nrpe: "/usr/lib/nagios/plugins/check_procs -w 2:75 -c 1:150 -u www-data -C apache -a /usr/sbin/apache" - hosts: merkel - depends: process - apache - master + hosts: kassia-sec, kassia-ftp, kassia-volatile # keyserver on raff - name: network service - http keyserver check: dsa_check_http_port!11371 - hosts: raff + hosts: kaufmann depends: process - apache2 - master # https on various hosts - name: network service - https check: check_https - hosts: ries, klecker, draghi, liszt, spohr + hosts: ries, klecker, draghi, liszt, spohr, widor, rietz depends: "process - apache2 - master" normal_check_interval: 120 - @@ -1628,7 +1632,7 @@ services: # draghi db.debian.org # merkel2 nm.debian.org # liszt lists.debian.org - hosts: ries, klecker, spohr, spohr2, draghi, merkel2, liszt + hosts: ries, klecker, spohr, spohr2, draghi, merkel2, liszt, widor, rietz depends: network service - https normal_check_interval: 60 @@ -1722,11 +1726,14 @@ services: # hostgroups: postgres81-hosts # depends: process - postresql81 - master #### + - + name: process - postresql84 - master + nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.4/bin/postgres'" + hostgroups: postgres84-hosts - name: process - postresql83 - master nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.3/bin/postgres -D /var/lib/postgresql/8.3/main -c config_file=/etc/postgresql/8.3/main/postgresql.conf'" hostgroups: postgres83-hosts - excludehosts: klecker #- # name: process - postresql83 - master udd # nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.3/bin/postgres -D /var/lib/postgresql/8.3/udd -c config_file=/etc/postgresql/8.3/udd/postgresql.conf'" @@ -1734,10 +1741,14 @@ services: - name: process - postresql83 - dak master nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.3/bin/postgres -D /var/lib/postgresql/8.3/dak -c config_file=/etc/postgresql/8.3/dak/postgresql.conf'" - hosts: ries, klecker + hosts: klecker, chopin + - + name: process - postresql84 - dak master + nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.4/bin/postgres -D /var/lib/postgresql/8.4/dak -c config_file=/etc/postgresql/8.4/dak/postgresql.conf'" + hosts: ries - - name: process - postresql83 - dak-dev master - nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.3/bin/postgres -D /var/lib/postgresql/8.3/dak-dev -c config_file=/etc/postgresql/8.3/dak-dev/postgresql.conf'" + name: process - postresql84 - dak-dev master + nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u postgres -C postgres -a '/usr/lib/postgresql/8.4/bin/postgres -D /var/lib/postgresql/8.4/dak-dev -c config_file=/etc/postgresql/8.4/dak-dev/postgresql.conf'" hosts: ries #### - @@ -1760,6 +1771,11 @@ services: nrpe: "/usr/lib/nagios/plugins/check_procs -w 1:1 -c 1: -u stunnel4 -C stunnel4 -a '/usr/bin/stunnel4 /etc/stunnel/postgres-udd.conf'" hosts: merkel, master + - + name: udd stunnel - master cert + nrpe: "/usr/lib/nagios/plugins/check_http -H localhost -p 8080 -S -C 14 -t 45" + hosts: samosa + #### #- # name: process - xenconsoled @@ -1882,6 +1898,22 @@ services: name: DNS SOA sync - alioth.debian.org check: "dsa_check_soas_add!alioth.debian.org!alioth.debian.org" hosts: global + - + name: DNS SOA sync - 2.5.1.1.8.0.0.8.d.8.0.1.0.0.2.ip6.arpa + check: "dsa_check_soas!2.5.1.1.8.0.0.8.d.8.0.1.0.0.2.ip6.arpa" + hosts: global + - + name: DNS SOA sync - a.5.1.1.8.0.0.8.d.8.0.1.0.0.2.ip6.arpa + check: "dsa_check_soas!a.5.1.1.8.0.0.8.d.8.0.1.0.0.2.ip6.arpa" + hosts: global + - + name: DNS SOA sync - 2.1.0.0.0.0.0.2.8.8.8.0.1.0.0.2.ip6.arpa + check: "dsa_check_soas!2.1.0.0.0.0.0.2.8.8.8.0.1.0.0.2.ip6.arpa" + hosts: global + - + name: DNS SOA sync - 2.6.a.0.4.6.5.6.1.0.0.0.2.0.0.0.8.d.8.0.1.0.0.2.ip6.arpa + check: "dsa_check_soas!2.6.a.0.4.6.5.6.1.0.0.0.2.0.0.0.8.d.8.0.1.0.0.2.ip6.arpa" + hosts: global ############ - name: ping alive check